Cosmos Labs told affected Cosmos EVM chains on Aug. 25 to coordinate validator halts as its security and engineering teams respond to an incident that has already impacted several networks. The company said chains in contact with it should work with validators to stop block production while a fix is investigated and prepared.

On decentralized proof-of-stake networks, a validator halt stops new transactions from settling and temporarily interrupts transfers, applications and withdrawals that rely on the chain. Cosmos Labs said its immediate focus is on identifying all vulnerable deployments, shipping a patched version and providing guidance for safe restarts.

KiiChain reports the largest disclosed loss

KiiChain said 148,326,583.15 KII were drained from wallets on Aug. 22. According to the project, the attacker repeated the technique 18 times before validators halted the network at block 9,355,723.

The team linked the incident to a Cosmos EVM vulnerability involving vesting accounts, staking operations and balance handling. KiiChain also said the attacker bridged part of the stolen assets to BNB Smart Chain through Hyperlane.

TAC and MANTRA detail separate impacts

TAC said an attacker exploited a weakness in the Cosmos EVM precompile layer on Aug. 22 and drained one account. Its validators then halted the network at block 24,671.

MANTRA said it stopped its chain on Aug. 20 after detecting activity involving two project-managed wallets. The network resumed after roughly 30 hours, restarting from a snapshot at block 17,449,398 without rolling back the chain's recorded state.

MANTRA stated that no user funds were affected and that balances were unchanged. It said the two addresses involved were part of its internal wallet infrastructure, but it has not yet published a full post-mortem or detailed asset accounting, and it did not quantify any attempted withdrawals or confirm whether project-controlled assets moved.

Broader questions remain unanswered

The latest incidents come after an earlier Cosmos EVM flaw tied to the ICS20 precompile. In that case, incorrect state handling during nested execution allowed the same token balance to be reused repeatedly within a single transaction, contributing to prior losses.

Cosmos Labs has not yet published a root cause for the current incident, an aggregate loss estimate, or confirmation that the same attacker was behind the activity seen on MANTRA, TAC and KiiChain.

Patch and incident report are the next key steps

For now, Cosmos Labs said the priority is to identify every affected deployment, distribute a patch and make sure networks can restart safely. Validators are expected to need coordinated upgrade instructions before block production resumes on halted chains.

The company said it plans to publish a detailed incident report covering the faulty component, affected versions, the exploitation timeline and total losses. It also intends to clarify whether the compromises on MANTRA, TAC and KiiChain came through the same code path. Until that information is available, some Cosmos EVM networks may remain halted or disable the affected functionality.

Source: crypto.news