- Cosmos Labs asked every Cosmos EVM chain in contact with it to halt validators on August 24 during an ongoing security incident.
- KiiChain says 148.3 million KII tokens moved out through the Hyperlane bridge to BNB Smart Chain across 18 transactions on August 22.
- MANTRA Chain, hit hardest by downtime, was listed by Cosmos Labs in March as having remediated the same underlying module, five months before this incident.
Cosmos Labs, the company behind the Cosmos EVM module, told every EVM chain in contact with it to halt validators on August 24. The module gives Cosmos SDK blockchains Ethereum-style smart contract compatibility, and a growing list of independent networks builds on top of it. Cosmos Labs said an incident report would follow once the situation is resolved, but has not named the vulnerability or given a restart timeline.
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…
— Cosmos Labs (@cosmoslabs_io) August 24, 2026
The advisory lands five months after Cosmos Labs published a fix for a related flaw in the same module and named MANTRA, one of the three chains hit this week, among the networks it identified as having already remediated it.
Three Chains, One Shared Module
MANTRA halted block production on August 20 after what it described as an attacker exploiting a vulnerability in an upstream dependency. The company said two of its own wallets were affected and no user funds were lost. The chain stayed down for roughly 30 hours before resuming on a patched release, and its token fell to an all-time low of $0.0041 during the outage.
KiiChain confirmed a separate attack on August 22. The network says 148.3 million KII tokens moved out through the Hyperlane bridge to BNB Smart Chain across 18 transactions. KiiChain has not published a dollar loss figure or identified the attacker. It joins a short list of chains that have halted outright after an exploit drained a large share of a token’s circulating supply, a pattern BounceBit went through earlier this year.
TAC, a third network built on the same Cosmos EVM base, said an exploited vulnerability had affected only its TAC token supply. Validators paused the chain while the team investigated.
The TAC team is currently investigating an exploited vulnerability on the Cosmos-based EVM side of TAC, affecting only $TAC supply.
We are working, together with the TAC validators on a temporary chain-halt that will happen over the next few minutes.
We will keep you posted on…
— TAC (🫰,✨️) (@TacBuild) August 22, 2026
A Bug MANTRA Was Told It Had Fixed
The pattern traces back to January, when an attacker used forged cross-chain messages to mint Saga’s dollar-pegged stablecoin without posting collateral, draining about $7 million through the module’s ICS20 precompile, the component that lets EVM contracts interact with Cosmos’s native token-transfer standard. It is not the first time an IBC-linked component in the Cosmos ecosystem has been the point of failure; Axelar disabled its Secret Network IBC bridge after a $4.67 million exploit earlier this year. Cosmos Labs shipped a fix for the ICS20 flaw in March, documented in security advisory GHSA-54gx-3cgr-7mfm, and listed 15 chains, MANTRA included, as having remediated it. Whether August’s exploit runs through the identical code path or a related weakness in the same dependency is something only Cosmos Labs’ promised report can settle. What the record already shows is that a chain marked as remediated went down again anyway.
Why “Remediated” May Not Mean Patched
Cosmos Labs has not said when the remaining halted chains will resume or what the patch involves. Until the incident report lands, the open question is not whether the module can be fixed, but whether a fix Cosmos Labs marks as delivered actually reaches every chain that depends on it.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.















