
A vulnerability in the shared Cosmos EVM software module has been linked to a multi-chain security incident that forced validators on several Cosmos-based networks to halt block production and resulted in large token losses on KiiChain and TAC.
The affected networks publicly identified so far include KiiChain, TAC, MANTRA and Nesa. Cosmos Labs, the organization behind the Cosmos technology stack, has acknowledged the security incident and instructed affected Cosmos EVM chains to halt validators while they assess and apply the required updates. Cosmos EVM’s public repository identifies the software as a plug-and-play system that adds Ethereum compatibility to Cosmos SDK-based blockchains and lists networks including MANTRA and TAC among its users.
The full scope of the incident remains unclear. Cosmos Labs has not publicly disclosed the complete vulnerability details or provided a definitive list of all affected chains. It has said that a full incident report will follow after the security situation is resolved.
Key takeaways:
- KiiChain reported the drainage of 148,326,583.15 KII after 18 exploit attempts.
- TAC reported that 2,985,651,403 TAC tokens were drained, with the affected amount valued at about $7.5 million.
- MANTRA halted its network but said user funds were not exploited.
- Nesa also halted operations after detecting malicious activity associated with a Cosmos EVM vulnerability.
- Cosmos Labs advised public chains running versions below v0.6.2 or v0.7.2 to halt and upgrade.
- The complete vulnerability chain and the full list of affected networks have not yet been publicly disclosed.
KiiChain provided the clearest publicly available account of the attack. The network said an attacker made 18 exploit attempts before draining 148,326,583.15 KII and forcing validators to halt the chain at block 9,355,723.
KiiChain said the vulnerability was located in the shared cosmos/evm module rather than in code specific to its own network. The reported loss represented roughly $9.7 million in token value at the time of the incident, although the amount realized by the attacker was substantially lower because of KII’s available liquidity.
According to the technical analysis cited in reporting on the incident, about 64.6 million KII was bridged to BNB Smart Chain and sold for approximately $1.61 million in BUSD, while roughly 80.7 million KII remained immobilized after the chain was halted.
The attack did not depend on simply creating new KII tokens. KiiChain said its total token supply was not increased. Instead, the exploit manipulated the balance represented in the EVM state so that an account could appear to have a much larger balance and then use that corrupted state to move real assets.
Technical analysis from GoPlus and information attributed to KiiChain indicate that the attack involved several defects working together. One publicly described component involved an arithmetic underflow in the EVM state database’s balance subtraction logic. When an account attempted to spend more than its available balance, the value could wrap around under unsigned integer arithmetic rather than being rejected.
The reported exploit path also involved calculating the address of a contract before deployment and associating that future address with a vesting account. After the contract was deployed at the predetermined address, the attacker was able to use the resulting account state as part of the exploit. KiiChain has said that three upstream defects were involved in its attack path, although only some of the technical details have been made public.
TAC was also affected. The network reported that an attacker drained 2,985,651,403 TAC tokens from a single account. TAC said the incident involved a vulnerability in the Cosmos EVM precompile layer and was not caused by TAC-specific code.
The amount drained represented about 62% of TAC’s circulating supply and was valued at approximately $7.5 million in reports about the incident. TAC said no new TAC was minted as a result of the attack and that total token supply remained unchanged.
TAC halted its network at block 24,671,475 after detecting the attack. The incident was separate from an earlier TAC Bridge security event reported in May 2026; the project’s TAC Bridge post-mortem concerns a different incident that affected its bridge infrastructure.
MANTRA was another network forced to stop operations. The project detected malicious activity associated with an upstream dependency and halted block production while it investigated the issue. MANTRA later resumed operations after deploying Cosmos EVM v8.4.0 and said that two wallets under its control were affected but that user funds were not exploited.
Nesa also reported malicious activity involving a Cosmos EVM vulnerability and halted its Layer-1 network. The project said it was working on a software fix and additional security measures before restoring services.
Some reports have circulated claims about a much larger value of NES associated with the Nesa incident, but those figures have not been independently confirmed. They are therefore not included in the confirmed loss figures for this incident.
Cosmos Labs has responded by asking affected networks to stop their validators and apply updated software. The emergency guidance specifically identifies public chains running versions below v0.6.2 or v0.7.2 as requiring an immediate halt and upgrade.
The response has also raised questions about the timing of the security disclosure. Technical analysis cited in coverage of the incident says a relevant change was publicly visible in the cosmos/evm GitHub repository on August 13, while version 0.7.2 was released on August 19 with security fixes.
KiiChain has criticized the disclosure process, arguing that the public availability of information about the fix before vulnerable networks had been fully protected may have helped attackers identify the underlying weakness. That is an allegation from KiiChain and should not be treated as a finding established by Cosmos Labs.
The Cosmos EVM security advisories page contains publicly disclosed vulnerabilities affecting the software, but it does not provide a complete public explanation of the latest incident described by the affected networks.
The incident also highlights the security implications of software shared across independent blockchain networks. Cosmos EVM is designed to provide a common Ethereum-compatible environment for Cosmos SDK chains, meaning a weakness in shared code can affect more than one network using the same component.
For now, the confirmed impact includes the KII and TAC token losses, operational halts on KiiChain, TAC, MANTRA and Nesa, and emergency upgrades for vulnerable Cosmos EVM deployments. The final number of affected chains, the full set of vulnerabilities involved and the total financial impact remain unknown.
Cosmos Labs has not yet released a complete post-incident technical report. Until that report is published, the publicly available evidence supports linking the incidents to the shared Cosmos EVM software, but does not establish the complete scope or every technical detail of the attacks.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


