A critical vulnerability in the shared Cosmos EVM module has triggered exploits and emergency chain halts on at least three independent blockchains, sending ripples through the ecosystem. Cosmos Labs confirmed the ongoing security incident on August 24, advising all chains using the module to pause block production as its teams scrambled to respond.
The flaw has already been exploited on the KiiChain and TAC networks, leading to the theft of hundreds of millions of tokens. A third network, MANTRA, also halted its chain for over a day as a preventative measure.
Cosmos Labs confirms impact from shared vulnerability
These events highlight the systemic risks inherent in modular blockchain frameworks, where a single bug in a shared component can create a cascading failure across multiple sovereign networks.
The incidents began to surface publicly around August 20, with each affected team initially investigating what appeared to be isolated issues. MANTRA, a Layer 1 blockchain focused on real-world assets, was the first to act. It halted its network at 8:10 p.m. ET on August 20 as a precaution, stating that two MANTRA-managed wallets were impacted but that no user funds were ever at risk.
After roughly 30 hours offline, MANTRA resumed block production on August 22. The team confirmed the issue was a vulnerability in an “upstream dependency” which was later identified as the Cosmos-EVM module. While MANTRA avoided a direct exploit of user assets, its tracked DeFi total value locked plummeted from over $548,575 to just $5,159 during the halt, demonstrating immediate impact on liquidity.
Two other chains were not as fortunate. On August 22, KiiChain disclosed it had been the victim of a significant exploit. An attacker repeatedly used the same technique 18 times to drain 148,326,583.15 KII tokens before validators managed to halt the chain at block 9,355,723.
The KiiChain team was quick to state the flaw was not in its own code. “The vulnerability is in Cosmos code… It sits in the shared Cosmos EVM module (cosmos/evm), which KiiChain runs unmodified,” the team said.
That same day, the TAC blockchain also paused all on-chain operations at block height 24,671,475. The team reported that an attacker exploited a flaw in the Cosmos EVM precompile layer to drain approximately 2.986 billion TAC tokens from a single account. Like KiiChain, the TAC team confirmed the defect was in the shared module, not in its own specific implementation.
Cosmos Labs advises chain halts in official response
After days of speculation, Cosmos Labs issued an official statement on August 24 confirming the breadth of the problem. “An ongoing security incident has impacted users of the Cosmos EVM module,” the organization announced. “We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.” This active response signals the severity of the underlying vulnerability.
The Cosmos EVM module is a crucial piece of software that allows blockchains built with the Cosmos SDK to gain compatibility with the Ethereum Virtual Machine. This enables them to run popular Ethereum-style smart contracts and dApps, features that many projects leverage to attract developers and users. This integration is vital for projects with an Ether goal, demonstrating the inherent value of such modules.
Halting a proof-of-stake network is a drastic but standard emergency procedure for critical bugs. It prevents new transactions from being processed, effectively freezing the ledger. This gives developers time to investigate the flaw, develop a patch, and coordinate a simultaneous restart with the network’s validators, preventing further losses.
Questions raised over silent security patch
As the dust settles, the technical details of the exploits are becoming clearer, and they point to different attack vectors stemming from the same core module. The KiiChain exploit was reportedly linked to a Cosmos EVM vulnerability involving vesting accounts, staking operations, and balance handling. Meanwhile, the attack on TAC targeted the EVM precompile layer, a component that provides efficient implementations of complex cryptographic functions.
More troubling for the community are reports concerning the disclosure of the fix. Community member “De” noted that the Cosmos engineering team had released an updated version of the module, v0.7.2, on GitHub on August 19. This update contained “important security fixes” but was allegedly pushed without a corresponding public security announcement, a practice often referred to as a “silent patch.”
This approach to patching is controversial. While it can prevent drawing immediate attention to a flaw, it also risks alerting sophisticated attackers who monitor code repositories for such changes. If these attackers identify the vulnerability before network operators have time to apply the patch, it creates a critical window for exploitation, which may have been the case here.
Not the first critical flaw in Cosmos EVM code
This is not the first time a vulnerability in a shared Cosmos component has led to widespread issues. In January 2026, an estimated $7 million was lost on the SagaEVM network due to a different flaw in the Cosmos EVM module. That earlier incident involved the ICS20 precompile, which handles cross-chain token transfers.
Cosmos Labs later issued security advisory ASA-2026-002 in March 2026 detailing a critical bug where incorrect state handling during nested contract calls could allow an attacker to use the same token balance multiple times within a single transaction.
Interestingly, the MANTRA team had reportedly assisted in investigating that previous issue, and a fix was included in a prior version of the module.
The recurrence of such a high-impact bug in the same shared codebase raises serious questions about its security auditing processes and can impact overall market confidence, potentially creating selling pressure in the altcoin sector.
The persistence of these vulnerabilities in core infrastructure components serves as a reminder that fundamental technological risks remain a primary concern for the long-term viability of many altcoin ecosystems.
Recovery plans in motion for affected chains
For the affected chains, the road to recovery is now the main focus. MANTRA has already successfully patched its network and resumed normal operations. KiiChain and TAC, which suffered direct financial losses, remain halted as their teams prepare for a coordinated restart. This will involve all validators applying a patched version of their node software at a predetermined block height.
The process is a delicate one, designed to bring the network back online in a consistent state without requiring a lengthy on-chain governance vote. Some assets stolen from KiiChain have already been tracked moving to the BNB Smart Chain via the Hyperlane bridge, complicating recovery efforts.
The situation is a live test of the resilience and coordination of these independent-yet-interconnected crypto projects. The broader crypto market, often characterized by weekly volume fluctuations, continues to monitor such security events.
Cosmos Labs has pointed teams with questions to its security contact. For an ecosystem built on the promise of interoperable and sovereign chains, ensuring the security of the common threads that bind them together has never been more critical.
