Cosmos EVM Chains Told to Halt After Attacks
Cosmos Labs has advised chains using its Cosmos EVM module to ask validators to halt operations while security and engineering teams respond to an ongoing security incident.
The warning follows incidents involving MANTRA, TAC and KiiChain since August 20. Cosmos Labs has not disclosed the full list of affected chains or confirmed whether all three attacks share the same vulnerability. It plans to release an incident report after the situation is resolved.
KiiChain Loses 148.3M KII Across 18 Attacks
KiiChain said an attacker drained 148,326,583.15 KII on August 22 by repeating the same technique 18 times before validators halted the network at block 9,355,723.
The halt stopped further attacks and left about 80.7 million of the stolen KII frozen on KiiChain. Roughly 67.6 million KII had already been bridged to BNB Smart Chain, including 3 million sent to a KuCoin deposit address.
KiiChain said it reproduced the exploit, traced the vulnerability to shared Cosmos EVM code and tested a fix before preparing a coordinated restart.
TAC Halts After Attacker Transfers 2.98B TAC
TAC said an attacker exploited a Cosmos EVM precompile vulnerability on August 22 to transfer 2,985,651,403 TAC from a single account.
The project said the incident was a drain rather than a mint, meaning no new TAC was created, and total supply remained unchanged. Validators stopped the network at block 24,671,475 while the team prepared remediation.
MANTRA Resumes After Roughly 30-Hour Network Halt
MANTRA had already stopped its Layer 1 after detecting malicious activity involving two project-managed wallets and later traced the vulnerability to its Cosmos EVM module.
The network resumed block production on August 22 after validators deployed version 8.4.0. MANTRA said no user funds were affected, and no blockchain rollback was required.
Cosmos Labs previously disclosed a separate critical ICS20 precompile flaw in March. That vulnerability could allow repeated use of the same token balance during nested EVM execution and was found in code running on 15 chains. Cosmos Labs marked that issue resolved after releasing a permanent fix in v0.6.0 and said all known affected chains had upgraded or applied mitigations.
Cosmos Labs has not confirmed that the August incidents involve that earlier flaw. Its halt recommendation remains the immediate safeguard while teams contain the current threat and await a full incident report.