Cosmos Labs Confirms Cosmos EVM Incident as 3 Chains Disclose Impact

2 hours ago 17

Cosmos Labs confirmed an ongoing security incident affecting users of the Cosmos EVM module. It advised chains in contact with it to ask validators to halt block production.

Three networks have now disclosed impact. KiiChain and TAC froze their chains after attackers drained accounts, while MANTRA restarted its mainnet.

3 Chains Traced Incidents to Cosmos EVM

Three networks disclosed security incidents within days of each other. All three named the Cosmos EVM module, a component that lets Cosmos SDK chains run Ethereum-style smart contracts.

MANTRA was first. BeInCrypto reported that the team halted the chain as a precaution amid a security incident in an upstream dependency. The team said two MANTRA-managed wallets were affected, and user balances were never impacted.

The network later informed users that the vulnerability was in the Cosmos-EVM module and that it had been fixed in version 8.4.0, allowing the network to resume normal block production.

Follow us on X to get the latest news as it happens

MANTRA Chain is producing blocks again.

The vulnerability in the Cosmos-EVM module has been fixed, the network has resumed, and no user funds were affected.

Thank you to everyone for your patience throughout the incident.

Review the full history of incident status updates… pic.twitter.com/IDVpw7H7Tp

— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain) August 22, 2026

KiiChain then disclosed an exploit. The team said that on August 22, an attacker repeated the same technique 18 times, draining 148,326,583.15 KII before validators halted the chain at block 9355723.

“The vulnerability is in Cosmos code, not KiiChain code. It sits in the shared Cosmos EVM module (cosmos/evm), which KiiChain runs unmodified,” the team said.

The chain remains halted. KiiChain said the network will resume through a coordinated binary upgrade at a predetermined block height, with all validators applying the update simultaneously. The process will not require an on-chain governance proposal.

TAC halted the same day at block 24,671,475 after an attacker drained a single account. The team said the defect sits in the shared module rather than in TAC-specific code.

Cosmos Labs has pointed teams with questions to its security contact and said it will publish an incident report once the situation is resolved. It has not yet described the cause.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Cosmos Labs Confirms Cosmos EVM Incident as 3 Chains Disclose Impact appeared first on BeInCrypto.

Read Entire Article