Cosmos Labs Urges EVM Chains to Halt Networks After Security Incident

Updated
Our disclosure policy →

Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

ShareTweetShareLinkedIn
Cosmos Labs Urges EVM Chains to Halt Networks After Security Incident

Highlights:

  • Cosmos Labs urged affected EVM chains to halt their networks while its teams investigate the security incident.
  • KiiChain lost more than 148 million KII after an attacker exploited its network 18 times.
  • MANTRA restarted after a 30-hour halt, while TAC stopped its network after an attacker drained one account.

Cosmos Labs, the team behind the open-source Cosmos EVM module, advised chains in contact with it to request validator halts. Cosmos Labs said its security and engineering teams are actively responding to the incident. However, it has not identified the exploited vulnerability, affected software versions, or every network exposed to the incident.

Advertisement

Banner

Cosmos EVM gives Cosmos SDK blockchains an integration layer for running Ethereum-compatible smart contracts and applications. Multiple independent blockchains use the shared software stack, so vulnerable code can create exposure across networks running affected configurations. Cosmos Labs contacted Cosmos EVM chains already communicating with its teams and advised them to coordinate emergency validator halts.

Validator halts prevent affected networks from processing new transactions while engineers investigate the incident and prepare mitigation measures. However, Cosmos Labs has not published public mitigation instructions or provided a timetable for restarting halted networks. In addition, it has also not quantified losses from the incident or identified every chain that received its warning.

MANTRA, KiiChain and TAC separately linked recent incidents to software within the shared Cosmos EVM stack. However, Cosmos Labs has not confirmed that all three projects suffered attacks through one vulnerability. It has also not confirmed whether one attacker targeted several Cosmos EVM networks.

Cosmos Labs Coordinates Response Across Affected Projects

KiiChain said an attacker exploited its network on Aug. 22 and drained 148,326,583.15 KII. The attacker repeated the technique 18 times before validators halted block production at block 9,355,723. KiiChain traced the exploited weakness to shared Cosmos EVM code rather than software developed specifically for its blockchain. The project linked the weakness to functions involving vesting accounts, staking operations, and balance handling.

TAC, an EVM network connected to TON, also reported an exploit affecting its Cosmos EVM infrastructure on Aug. 22. TAC said an attacker exploited the Cosmos EVM precompile architecture and drained assets from one account. TAC validators stopped block production at block 24,671,475 after the project detected the attack.

Meanwhile, MANTRA halted its mainnet after detecting malicious activity involving two project-controlled wallets. MANTRA, an EVM Layer 1 focused on real-world assets, traced the incident to its Cosmos EVM implementation. The network recorded block 17,449,398 around 23:13 UTC on Aug. 20 before stopping block production.

The network resumed block production around 05:30 UTC on Aug. 22 without rolling back its recorded transaction history. MANTRA said the incident affected two addresses under its control but did not result in exploited user funds.

Earlier EVM Flaw Raises Fresh Questions

The August incidents follow an earlier Cosmos EVM vulnerability involving the ICS20 precompile that developers disclosed in March. The advisory described incorrect state handling during nested execution that could allow repeated use of the same token balance. Attackers exploited the earlier weakness on SagaEVM in January and caused about $7 million in estimated losses. Cosmos Labs later identified 15 chains running code that contained the relevant vulnerability.

Cosmos Labs has not linked the earlier ICS20 vulnerability to the August incidents involving MANTRA, KiiChain and TAC. It has also not confirmed whether the KiiChain and TAC attacks involved one attacker or the same code path.

Cosmos Labs said it will publish a full incident report after its security and engineering teams resolve the ongoing incident. The report is expected to identify the affected component, vulnerable versions, exploitation timeline, and confirmed losses across affected networks.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

More by this author