TLDR
- Cosmos Labs urged affected Cosmos EVM chains to halt validators on Aug. 25 following an active security incident.
- KiiChain reported 148,326,583.15 KII drained across 18 repeated attacks on Aug. 22.
- TAC halted its network at block 24,671 after one account was drained via a Cosmos EVM precompile exploit.
- MANTRA resumed block production after roughly 30 hours and said user balances were unchanged.
- Cosmos Labs has not disclosed affected chains, vulnerability details, or total losses publicly.
Multiple blockchain networks built on the Cosmos EVM software stack were forced to halt operations in late August 2026 after Cosmos Labs identified an active security incident targeting its shared module.
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…
— Cosmos Labs (@cosmoslabs_io) August 24, 2026
Cosmos EVM is a plug-and-play layer that gives Cosmos SDK chains compatibility with the Ethereum Virtual Machine. Because it is shared software, a flaw in one module can affect every network running it.
Cosmos Labs said its security and engineering teams were actively responding. It urged affected chains to ask their validators to stop block production while a fix was developed.
KiiChain and TAC Suffer Direct Losses
KiiChain confirmed that an attacker drained 148,326,583.15 KII from wallets on Aug. 22. The attacker repeated the technique 18 times before validators halted the network at block 9,355,723.
KiiChain linked the attack to a vulnerability involving vesting accounts, staking operations, and balance handling within the Cosmos EVM module. Part of the stolen assets were bridged to BNB Smart Chain through the Hyperlane bridge.
TAC also reported an exploit on Aug. 22. An attacker used a weakness in the Cosmos EVM precompile layer to drain one account before validators halted the network at block 24,671.
Both projects confirmed unauthorized asset movements. Cosmos Labs has not published a combined loss figure or confirmed whether the same attacker was behind both incidents.
MANTRA Restarts After 30-Hour Halt
MANTRA halted its network on Aug. 20 after detecting unusual activity involving two project-managed wallets. The team traced the issue to its Cosmos EVM module.
After deploying an updated release, MANTRA coordinated a validator restart. The network resumed block production after roughly 30 hours, restarting from a snapshot at block 17,449,398 without rolling back the chain’s recorded state.
MANTRA said no user funds were affected and that the two impacted addresses belonged to its internal wallet infrastructure. A full post-mortem has not yet been published.
The August incidents follow an earlier Cosmos EVM flaw involving the ICS20 precompile. A March 2026 security advisory described incorrect state handling during nested execution that allowed the same token balance to be used more than once in a single transaction.
That earlier flaw caused an estimated $7 million loss on SagaEVM in January 2026. It remains unconfirmed whether the August attacks used the same code path or a separate vulnerability.
Cosmos Labs said it plans to release a full incident report once the situation is contained. That report is expected to identify the faulty component, affected versions, and total losses across all chains.
Until the report is published, users should monitor official chain status pages and avoid transactions through unverified interfaces.







