Cosmos Labs Urges EVM Chains to Halt Networks After Security Incident
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Cosmos Labs urged affected EVM chains to halt their networks while its teams investigate the security incident.
- KiiChain lost more than 148 million KII after an attacker exploited its network 18 times.
- MANTRA restarted after a 30-hour halt, while TAC stopped its network after an attacker drained one account.
Cosmos Labs, the team behind the open-source Cosmos EVM module, advised chains in contact with it to request validator halts. Cosmos Labs said its security and engineering teams are actively responding to the incident. However, it has not identified the exploited vulnerability, affected software versions, or every network exposed to the incident.
Cosmos Labs Urges EVM Chains to Halt as Security Incident Spreads
Cosmos Labs said an ongoing security incident involving the Cosmos EVM module has affected users, with its security and engineering teams advising contacted Cosmos EVM chains to have validators halt their networks… pic.twitter.com/03jCweSksI
— Wu Blockchain (@WuBlockchain) August 25, 2026
Cosmos EVM gives Cosmos SDK blockchains an integration layer for running Ethereum-compatible smart contracts and applications. Multiple independent blockchains use the shared software stack, so vulnerable code can create exposure across networks running affected configurations. Cosmos Labs contacted Cosmos EVM chains already communicating with its teams and advised them to coordinate emergency validator halts.
Validator halts prevent affected networks from processing new transactions while engineers investigate the incident and prepare mitigation measures. However, Cosmos Labs has not published public mitigation instructions or provided a timetable for restarting halted networks. In addition, it has also not quantified losses from the incident or identified every chain that received its warning.
MANTRA, KiiChain and TAC separately linked recent incidents to software within the shared Cosmos EVM stack. However, Cosmos Labs has not confirmed that all three projects suffered attacks through one vulnerability. It has also not confirmed whether one attacker targeted several Cosmos EVM networks.
Cosmos Labs Coordinates Response Across Affected Projects
KiiChain said an attacker exploited its network on Aug. 22 and drained 148,326,583.15 KII. The attacker repeated the technique 18 times before validators halted block production at block 9,355,723. KiiChain traced the exploited weakness to shared Cosmos EVM code rather than software developed specifically for its blockchain. The project linked the weakness to functions involving vesting accounts, staking operations, and balance handling.
We're aware of a security incident affecting KiiChain and KII. Our team is responding alongside our security and infrastructure partners.
The issue stems from a vulnerability in the EVM module, which allowed the attacker to move funds off KiiChain via Hyperlane to BSC. The chain…
— KiiChain (@KiiChainio) August 23, 2026
TAC, an EVM network connected to TON, also reported an exploit affecting its Cosmos EVM infrastructure on Aug. 22. TAC said an attacker exploited the Cosmos EVM precompile architecture and drained assets from one account. TAC validators stopped block production at block 24,671,475 after the project detected the attack.
On August 22 an attacker exploited a vulnerability in the Cosmos EVM precompile layer and drained a single account on TAC. We halted the chain at block 24,671,475 to stop it. The defect is not in TAC-specific code. It sits in the shared Cosmos EVM module, and several other chains…
— TAC (🫰,✨️) (@TacBuild) August 24, 2026
Meanwhile, MANTRA halted its mainnet after detecting malicious activity involving two project-controlled wallets. MANTRA, an EVM Layer 1 focused on real-world assets, traced the incident to its Cosmos EVM implementation. The network recorded block 17,449,398 around 23:13 UTC on Aug. 20 before stopping block production.
We're aware of an incident affecting MANTRA Chain and have halted the chain as a precaution while we investigate. All endpoints and transactions are currently frozen.
This means deposits and withdrawals to/from MANTRA Chain are temporarily affected. If you're unsure how this…
— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain) August 21, 2026
The network resumed block production around 05:30 UTC on Aug. 22 without rolling back its recorded transaction history. MANTRA said the incident affected two addresses under its control but did not result in exploited user funds.
Earlier EVM Flaw Raises Fresh Questions
The August incidents follow an earlier Cosmos EVM vulnerability involving the ICS20 precompile that developers disclosed in March. The advisory described incorrect state handling during nested execution that could allow repeated use of the same token balance. Attackers exploited the earlier weakness on SagaEVM in January and caused about $7 million in estimated losses. Cosmos Labs later identified 15 chains running code that contained the relevant vulnerability.
SagaEVM has been paused at block height 6593800 in response to a confirmed exploit on the SagaEVM chainlet.
Mitigation is underway, and the team is fully focused on a solution.
Further updates will follow once details are confirmed.
— Saga AI Labs (@SagaAILabs) January 21, 2026
Cosmos Labs has not linked the earlier ICS20 vulnerability to the August incidents involving MANTRA, KiiChain and TAC. It has also not confirmed whether the KiiChain and TAC attacks involved one attacker or the same code path.
Cosmos Labs said it will publish a full incident report after its security and engineering teams resolve the ongoing incident. The report is expected to identify the affected component, vulnerable versions, exploitation timeline, and confirmed losses across affected networks.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







