Cosmos Labs has told affected networks that are in contact with its team to suspend operations during an ongoing security incident tied to the Cosmos EVM module. The warning followed a series of disclosures from KiiChain, TAC and MANTRA, each of which linked recent attacks or emergency responses to problems in shared Cosmos EVM infrastructure rather than chain-specific code.
Cosmos Labs has not publicly said whether all of the incidents stem from one vulnerability, nor has it identified every network asked to halt. The company said it plans to publish an incident report after the matter is resolved.
KiiChain details repeated drains
KiiChain said an attacker drained 148,326,583.15 KII from wallets on Aug. 22, using the same method 18 times against different targets. The network said it detected the activity internally, halted the chain at block 9,355,723 and froze the remaining funds.
According to KiiChain, the root cause was a vulnerability in the shared Cosmos EVM module, not in KiiChain-specific code. It said the issue was caused by three upstream defects, including an underflow in the staking precompile when a post-delegation balance was written back to the EVM, along with two other bugs that were not disclosed publicly.
Shared risk across Cosmos EVM chains
KiiChain said the same class of vulnerability affected Cosmos EVM chains with vesting accounts enabled and linked the issue to the compromises of MANTRA and TAC during the same week. It also argued that an emergency halt would have reduced the danger faster than a software upgrade, because validators need time to review and deploy patches.
One fix for a flaw had been made public on Aug. 19, according to KiiChain, but affected networks were not warned in advance and the release was not clearly marked as a critical update. By the time the patch reached some chains two days later, KiiChain said, it had been bundled with unrelated changes and did not include a recommendation to halt. MANTRA had already been exploited by that point, according to KiiChain’s account.
TAC and MANTRA responses
TAC said an attacker exploited a vulnerability in the Cosmos EVM precompile layer on the same day, draining a single account. The chain then halted to stop the attack. TAC said the flaw was not in its own custom code.
The network reported that about 2,985,651,403 TAC moved between accounts. It added that no new tokens were minted, the total supply did not change, and only TAC was affected.
MANTRA said it halted its Layer 1 network for roughly 30 hours as a precaution. It later said the root cause had been identified, the immediate threat contained and no user funds had been exploited. According to MANTRA, the incident touched two wallet addresses, and the network resumed operations after a patch was deployed.
What is confirmed so far
At this stage, the public record shows multiple Cosmos EVM chains responding to security issues that their teams say were tied to shared infrastructure. What remains unresolved is whether the incidents all originated from a single flaw or from several related defects within the Cosmos EVM module.
The next confirmed step is a formal incident report from Cosmos Labs once the case is closed. Until then, the clearest guidance on the situation remains the company’s request for affected networks working with its team to halt operations while the investigation and remediation continue.
Source: cryptopotato.com