Cosmos EVM Module Security Incident Halts Multiple Chains

Cosmos EVM Module Security Incident Halts Multiple Chains

First seen 25 Aug 2026, 06:23 UTC CryptobriefingCoingabbar 69.0

Article Content

Browse articles
ThreatCluster

On August 24, 2026, Cosmos Labs reported an active security incident affecting chains using its Cosmos EVM module, prompting a halt of validator operations across multiple networks. The incident follows unauthorized fund movements on KiiChain, TAC, and MANTRA earlier in August. KiiChain confirmed a loss of over 148 million KII tokens due to repeated attacks exploiting a vulnerability in the EVM module. TAC halted operations after one account was drained, while MANTRA experienced a 30-hour shutdown due to issues with two project-managed wallets. Cosmos Labs has not disclosed the total loss figure or specific mitigation steps but plans to release a full incident report once the situation is resolved. Currently, there is no public timetable for restarting the affected chains. The vulnerability potentially impacts all chains running the same EVM code, emphasizing the need for immediate action.

Key Points: • Cosmos Labs confirmed a security incident affecting its EVM module on August 24, 2026. • KiiChain reported a loss of over 148 million KII tokens due to repeated attacks exploiting the vulnerability. • Affected chains, including TAC and MANTRA, have halted operations as a precautionary measure.

Timeline

2026-08-20
MANTRA Chain halts operations
MANTRA Chain experienced a 30-hour shutdown due to issues with two managed wallets before resuming operations.
Coingabbar
2026-08-22
KiiChain suffers major loss
KiiChain confirmed the draining of 148,326,583.15 KII tokens across 18 attacks before validators halted the network.
Coingabbar
2026-08-22
TAC halts block production
TAC halted operations after reporting an account was drained due to a vulnerability in the EVM precompile layer.
Coingabbar
2026-08-24
Cosmos Labs issues security advisory
Cosmos Labs confirmed an active security incident and urged all affected chains to halt validator operations while investigations are ongoing.
Coingabbar
2026-08-25
Incident reported by multiple outlets
Cryptobriefing and Coingabbar reported on the ongoing security incident, highlighting the need for immediate action from affected chains.
Cryptobriefing