CoinTrust

Cosmos EVM Vulnerability Triggers Attacks Across Three Networks

Cosmos

A vulnerability in the shared Cosmos EVM software has triggered attacks on three blockchain networks, prompting Cosmos Labs to urge affected projects to stop producing blocks and apply security updates. The incident highlights the risks associated with widely reused infrastructure, where a weakness in a common software component can expose multiple independent networks to the same threat.

The affected networks are Mantra, TAC and KiiChain, which were targeted between Aug. 20 and Aug. 22. Mantra has since restored operations after deploying an updated version of its software, while TAC and KiiChain have remained halted as teams assess the vulnerability and implement necessary safeguards.

Cosmos EVM is an open-source module that enables blockchains built with the Cosmos SDK to support Ethereum-compatible smart contracts. Because the same software can be integrated across numerous networks, a vulnerability in the module can potentially create a broader ecosystem-level security risk.

Cosmos Labs has advised networks running Cosmos EVM versions earlier than 0.6.2 or 0.7.2 to immediately halt block production and install the recommended patches. The company has not disclosed how many networks could potentially be exposed to the vulnerability.

KiiChain Reports Loss of 148 Million Tokens

KiiChain has provided the most detailed account of the attacks. The network said an attacker withdrew about 148 million KII tokens through 18 separate transactions involving different wallets.

After KiiChain halted its network, approximately 80.7 million KII were frozen. Another 67.6 million KII were transferred through Hyperlane to BNB Smart Chain. Of that amount, about 64.6 million tokens were sold through a decentralized exchange for roughly $1.61 million, while 3 million KII were transferred to a KuCoin deposit address.

TAC also reported suspicious movement involving about 2.99 billion TAC tokens, representing roughly 62% of its circulating supply. The network subsequently stopped block production while investigating the incident.

Mantra said the attack was limited to two wallets under its control and did not affect customer, exchange or partner funds. The network later resumed operations after moving to a patched software version.

Vulnerability Linked to Shared Cosmos EVM Code

KiiChain said the underlying problem was located in Cosmos EVM rather than its own blockchain-specific code. The exploit reportedly combined three separate defects, including an overflow issue involving the staking precompilation and the EVM balance.

The vulnerability allowed an attacker to manipulate account behavior in a way that enabled the withdrawal of real funds from targeted wallets without increasing the network’s overall token supply.

According to the KiiChain account, the attacker first created a contract at a predetermined address and then converted it into a vesting account. The attacker subsequently delegated one wei more than the available balance, causing an incorrect internal value and enabling the withdrawal of actual funds.

Mantra developers separately indicated that the incident involved a weakness in an upstream dependency used by the blockchain, although they did not provide additional technical details.

KiiChain has also raised concerns that the underlying bugs may not have been fully addressed publicly. The team therefore suggested that applying a single Cosmos Labs update might not, by itself, completely remove the security risk.

Disclosure Process Draws Criticism

The incident has also prompted criticism of Cosmos Labs’ vulnerability disclosure process. The company placed a patch in a public repository on Aug. 19. KiiChain said affected networks were not notified beforehand and that the release was not initially identified as a critical security update.


The warning reportedly came two days later, leaving blockchain developers with a difficult choice between rapidly updating validators after the public release or continuing to operate potentially vulnerable networks.

KiiChain argued that the delay may have created an opportunity for attackers to exploit the weakness before affected projects could respond.


Second Major Cosmos EVM Security Incident in 2026

The latest attacks follow another major Cosmos EVM-related security incident earlier this year. In January, a vulnerability in another component was exploited against Saga EVM, resulting in losses estimated at about $7 million.

Cosmos Labs later said the affected code had been integrated into the main branch in July 2024 and was operating across 15 blockchains, although the feature was disabled on six networks. One network was compromised before other projects took protective measures. A permanent fix was released in version 0.6.0 in March, with Mantra among the teams credited with helping test the patch.

The latest incident underscores the need for stronger coordination between shared infrastructure developers and blockchain operators, particularly when critical vulnerabilities can affect multiple networks simultaneously.

The attacks also come amid broader concerns about the growing sophistication and scalability of threats facing digital-asset infrastructure. Participants at the Wyoming Blockchain Symposium had previously discussed how AI agents could potentially lower the cost and increase the scale of attacks targeting cryptocurrency projects and users.

Exit mobile version