Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

MANTRA, KiiChain and TAC were all hit within days of each other, five months after Cosmos Labs listed MANTRA as having already fixed a related bug in the same module

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 25, 2026
in Security & Hacks
0 0
Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

Image by Gerd Altmann from Pixabay/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle
  • Cosmos Labs asked every Cosmos EVM chain in contact with it to halt validators on August 24 during an ongoing security incident.
  • KiiChain says 148.3 million KII tokens moved out through the Hyperlane bridge to BNB Smart Chain across 18 transactions on August 22.
  • MANTRA Chain, hit hardest by downtime, was listed by Cosmos Labs in March as having remediated the same underlying module, five months before this incident.

Cosmos Labs, the company behind the Cosmos EVM module, told every EVM chain in contact with it to halt validators on August 24. The module gives Cosmos SDK blockchains Ethereum-style smart contract compatibility, and a growing list of independent networks builds on top of it. Cosmos Labs said an incident report would follow once the situation is resolved, but has not named the vulnerability or given a restart timeline.

An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…

— Cosmos Labs (@cosmoslabs_io) August 24, 2026

The advisory lands five months after Cosmos Labs published a fix for a related flaw in the same module and named MANTRA, one of the three chains hit this week, among the networks it identified as having already remediated it.

Three Chains, One Shared Module

MANTRA halted block production on August 20 after what it described as an attacker exploiting a vulnerability in an upstream dependency. The company said two of its own wallets were affected and no user funds were lost. The chain stayed down for roughly 30 hours before resuming on a patched release, and its token fell to an all-time low of $0.0041 during the outage.

KiiChain confirmed a separate attack on August 22. The network says 148.3 million KII tokens moved out through the Hyperlane bridge to BNB Smart Chain across 18 transactions. KiiChain has not published a dollar loss figure or identified the attacker. It joins a short list of chains that have halted outright after an exploit drained a large share of a token’s circulating supply, a pattern BounceBit went through earlier this year.

TAC, a third network built on the same Cosmos EVM base, said an exploited vulnerability had affected only its TAC token supply. Validators paused the chain while the team investigated.

The TAC team is currently investigating an exploited vulnerability on the Cosmos-based EVM side of TAC, affecting only $TAC supply.

We are working, together with the TAC validators on a temporary chain-halt that will happen over the next few minutes.

We will keep you posted on…

— TAC (🫰,✨️) (@TacBuild) August 22, 2026

A Bug MANTRA Was Told It Had Fixed

The pattern traces back to January, when an attacker used forged cross-chain messages to mint Saga’s dollar-pegged stablecoin without posting collateral, draining about $7 million through the module’s ICS20 precompile, the component that lets EVM contracts interact with Cosmos’s native token-transfer standard. It is not the first time an IBC-linked component in the Cosmos ecosystem has been the point of failure; Axelar disabled its Secret Network IBC bridge after a $4.67 million exploit earlier this year. Cosmos Labs shipped a fix for the ICS20 flaw in March, documented in security advisory GHSA-54gx-3cgr-7mfm, and listed 15 chains, MANTRA included, as having remediated it. Whether August’s exploit runs through the identical code path or a related weakness in the same dependency is something only Cosmos Labs’ promised report can settle. What the record already shows is that a chain marked as remediated went down again anyway.

Why “Remediated” May Not Mean Patched

Cosmos Labs has not said when the remaining halted chains will resume or what the patch involves. Until the incident report lands, the open question is not whether the module can be fixed, but whether a fix Cosmos Labs marks as delivered actually reaches every chain that depends on it.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto Hacks
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token
Security & Hacks

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

by Saravana Kumar Mahendran
August 25, 2026

Kylie Jenner's X account, which has 39.5 million followers, posted a Pump.fun page and a Solana contract address for a...

Read moreDetails

BounceBit Shuts Down Its Blockchain After Exploit Drains a Quarter of BB’s Circulating Supply

August 22, 2026
MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability

MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability

August 21, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain’s Old Playbook

Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain’s Old Playbook

August 19, 2026
Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

August 14, 2026
Boltz Hands Over Control, But Won’t Say Who’s Taking It or How Much Was Lost

Boltz Hands Over Control, But Won’t Say Who’s Taking It or How Much Was Lost

August 13, 2026

Recommended

  • All
  • Crypto News Today
Metaplanet Moves 1,000 BTC to Coinbase Prime

Metaplanet Moves 1,000 BTC to Coinbase Prime Amid Sale Speculation

August 25, 2026
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026
Blockchain Association Asks Regulators to Keep Stablecoin KYC Checks at the Issuer Level

Blockchain Association Asks Regulators to Keep Stablecoin KYC Checks at the Issuer Level

August 25, 2026
Arthur Hayes Says Bitcoin Bull Run Has Begun as Liquidity Improves

Arthur Hayes Says Bitcoin Bull Run Has Begun as Liquidity Improves

August 25, 2026
Photo by Yiğit Ali Atasoy on Unsplash/Edited by Cryip

Bitmine Buys 32,447 ETH, Pushing Holdings to 5.85 Million Tokens

August 24, 2026
Base Defends Builder Support After Criticism Over Its Ecosystem

Base Defends Builder Support After Criticism Over Its Ecosystem

August 24, 2026
Saylor's Strategy Makes No BTC Purchase, Raises USD Reserve to $5.10B

Saylor’s Strategy Makes No BTC Purchase, Raises USD Reserve to $5.10B

August 24, 2026
Upbit and Bithumb Flag SAND for Caution, the Review That Has Ended in Delisting

Upbit and Bithumb Flag SAND for Caution, the Review That Has Ended in Delisting

August 24, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed
  • Metaplanet Moves 1,000 BTC to Coinbase Prime Amid Sale Speculation
  • Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.