
Cosmos Labs has urged public blockchains using vulnerable versions of its Cosmos EVM module to immediately halt block production and upgrade their software, following attacks that disrupted MANTRA, KiiChain and TAC.
The warning came as Cosmos Labs’ security and engineering teams investigated an ongoing incident involving Cosmos EVM, the software module that enables blockchains built with the Cosmos SDK to run Ethereum-compatible smart contracts. The company initially advised affected networks already in contact with its team to instruct validators to stop operations while the investigation continued.
Cosmos Labs later issued a broader warning on August 25, saying public chains running Cosmos EVM below version 0.6.2 or 0.7.2 should immediately halt their blockchains and upgrade to releases containing the patches. The company has not publicly disclosed the technical root cause of the current incident or provided a complete list of potentially affected networks. Cosmos EVM’s security repository lists the project’s vulnerability disclosures and coordinated security policy.
The incidents reported by MANTRA, KiiChain and TAC occurred between August 20 and August 22. Each project has connected its incident to the shared Cosmos EVM software rather than to code developed specifically for its own chain.
MANTRA was the first of the three networks to report an incident. The project halted its blockchain after identifying suspicious activity and later said two wallets managed by MANTRA had been affected. It said user funds, exchange funds and partner funds were not affected. MANTRA subsequently deployed a patched version, reported as version 8.4.0, and resumed block production on August 22.
KiiChain suffered the largest publicly disclosed loss from the latest series of attacks. According to the project’s account, an attacker carried out 18 separate attacks on August 22 and withdrew 148,326,583.15 KII before validators halted the network at block 9,355,723.
KiiChain said the vulnerability was located in the shared cosmos/evm module and was not part of KiiChain’s own code. The project said the exploit involved several defects, including an issue involving the staking precompile and EVM balance handling. According to KiiChain’s explanation, the attacker was able to deploy a contract at a pre-calculated address, have that address treated as a vesting account and manipulate account balances in a way that enabled the withdrawal of real funds. KiiChain said the attack did not increase the total token supply.
Most of the stolen KII remained connected to the halted network. KiiChain reported that about 80.7 million KII were frozen after the halt. A further 67.6 million KII was transferred through Hyperlane to BNB Smart Chain, with approximately 64.6 million KII sold on a decentralised exchange for about $1.61 million and another 3 million KII sent to a KuCoin deposit address.
TAC also halted its blockchain on August 22 after an attacker drained a single account. The network stopped producing blocks at 24,671,475. TAC said the defect originated in the Cosmos EVM module rather than in TAC-specific code. Reports placed the amount involved at about 2.99 billion TAC, equivalent to roughly 62% of the token’s circulating supply at the time.
Cosmos Labs has not yet publicly confirmed that every incident was caused by one identical vulnerability, and it has not published the full technical findings behind the attacks. The company has said it will provide a comprehensive incident report after the security work is completed.
The emergency response has also drawn criticism over the timing of the security fixes. The Cosmos EVM project maintains a public GitHub repository, where its releases and security information are visible. The project’s release history shows security-related patch releases, while reporting from KiiChain has raised concerns about the timing between the publication of a fix and the notification of affected networks.
KiiChain has argued that the disclosure process gave attackers an opportunity to study the public changes before vulnerable networks had completed upgrades. That criticism is an allegation from the affected network; Cosmos Labs has not publicly released a complete communication timeline establishing when each affected chain was notified or responded to the criticism in a detailed public post-mortem.
The Cosmos EVM incident is not the first serious security problem involving the shared codebase this year. In January, Saga EVM was affected by a separate vulnerability involving the ICS20 precompile, according to a Cosmos EVM security advisory published in March. Cosmos said that earlier incident resulted in losses estimated at about $7 million and involved incorrect state handling during nested EVM execution. A permanent fix for that vulnerability was released in version 0.6.0.
Cosmos’ security policy calls for vulnerabilities to be reported privately and kept confidential until they have been resolved and disclosed. The project says researchers can report vulnerabilities through its security email or its HackerOne bug bounty programme. The policy also asks researchers to avoid publicly posting vulnerability information before the issue has been resolved.
The current incident highlights the security exposure created when several independent blockchains rely on the same software component. A defect in a shared module can affect multiple networks even when those networks do not share the same application or operational teams. In this case, the common dependency has become the focus of an emergency response across several separate chains.
For operators, Cosmos Labs’ latest instruction is straightforward: public chains using Cosmos EVM below v0.6.2 or v0.7.2 should halt block production and upgrade to patched releases. The company has also asked other Cosmos EVM operators that have not yet contacted its security team to do so while the investigation continues.
As of August 26, MANTRA has resumed production after its upgrade, while KiiChain and TAC have remained halted according to their publicly reported incident updates. The final scope of the incident, the complete technical cause and the number of other networks exposed remain pending further disclosure from Cosmos Labs.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


