Cosmos Labs urged affected Cosmos EVM chains to request validator halts on Aug. 25 as its security and engineering teams responded to an incident that had already reached multiple networks, crypto.news reported .
A shared software stack
Cosmos EVM is a software module that lets Cosmos SDK chains execute Ethereum-compatible smart contracts, so a vulnerability in a common component can expose independent networks running affected versions. Cosmos Labs did not identify the underlying vulnerability, the affected chains or total losses in its initial statement, and said it would publish an incident report after the situation was resolved. It did not publish a software version, mitigation instructions or a restart schedule, likely to avoid revealing exploitable details before chains are protected, and directed other teams with questions to its security email.
What the affected chains disclosed
KiiChain said an attacker drained 148,326,583.15 KII from wallets on Aug. 22, repeating the technique 18 times before validators stopped the network at block 9,355,723. The team linked the attack to a Cosmos EVM vulnerability involving vesting accounts, staking operations and balance handling, and said part of the assets was bridged to BNB Smart Chain through Hyperlane. TAC separately said an attacker exploited a weakness in the Cosmos EVM precompile layer on Aug. 22 and drained one account before validators halted the network at block 24,671.
MANTRA and the bigger picture
MANTRA stopped its network on Aug. 20 after detecting activity in two project-managed wallets and resumed block production after a roughly 30-hour halt, saying user balances were unchanged. A halt prevents new transactions from settling while developers investigate, temporarily blocking transfers, applications and withdrawals that depend on the chain. The incidents follow an earlier Cosmos EVM flaw in the ICS20 precompile, where incorrect state handling during nested execution allowed the same balance to be used repeatedly, causing an estimated $7 million loss on SagaEVM in January. Whether the August attacks used that exact flaw or a separate vulnerability remains unconfirmed, and Cosmos Labs has not yet published an aggregate loss figure or confirmed whether the same attacker controlled every address involved.
The episode recalls MANTRA’s earlier halt after its own exploit .


