Key Takeaways
- On August 25, Cosmos Labs issued an emergency directive for all impacted Cosmos EVM-based chains to immediately halt validator operations due to an ongoing security breach.
- An attacker successfully extracted 148,326,583.15 KII tokens from KiiChain through 18 successive exploitation attempts on August 22.
- The TAC network suspended operations at block height 24,671 following the drainage of one account through a Cosmos EVM precompile vulnerability.
- Following approximately 30 hours of downtime, MANTRA restored block production and confirmed no impact to user account balances.
- No public disclosure has been made by Cosmos Labs regarding which chains were compromised, technical vulnerability specifics, or aggregate financial damage.
Several blockchain platforms operating on the Cosmos EVM software infrastructure were compelled to cease operations during late August 2026 when Cosmos Labs detected an active security compromise affecting its shared module architecture.
The Cosmos EVM functions as a modular integration layer that enables Cosmos SDK-based blockchains to achieve compatibility with Ethereum Virtual Machine protocols. Due to its shared-software architecture, any security weakness in the core module creates systemic risk across all networks implementing it.
According to Cosmos Labs, both security and engineering divisions mobilized an immediate response. The organization issued urgent guidance to affected blockchain networks, instructing their validator operators to immediately suspend block production pending the deployment of a security patch.
KiiChain and TAC Report Confirmed Financial Losses
KiiChain disclosed that a malicious actor successfully extracted 148,326,583.15 KII tokens from user wallets on August 22. The perpetrator executed the exploitation method 18 consecutive times before network validators implemented an emergency halt at block height 9,355,723.
According to KiiChain’s analysis, the attack exploited a security weakness involving the interaction between vesting account mechanisms, staking protocol operations, and balance management functions within the Cosmos EVM module. A portion of the compromised assets were subsequently transferred to BNB Smart Chain using the Hyperlane cross-chain bridge protocol.
TAC similarly disclosed an exploitation event on August 22. An attacker leveraged a vulnerability in the Cosmos EVM precompile infrastructure layer to drain funds from a single account before validators executed a network halt at block 24,671.
Both blockchain projects have verified unauthorized asset transfers occurred. However, Cosmos Labs has not released consolidated financial impact data or confirmed whether a single threat actor orchestrated both incidents.
MANTRA Network Resumes Operations Following 30-Hour Suspension
MANTRA initiated a network shutdown on August 20 after its monitoring systems identified suspicious activity associated with two wallets under project management. Investigation revealed the anomaly originated within its Cosmos EVM module implementation.
Following the deployment of a patched software version, MANTRA orchestrated a coordinated validator restart process. Network operations resumed after approximately 30 hours of downtime, with block production restarting from a state snapshot captured at block 17,449,398 without implementing a chain state rollback.
MANTRA representatives confirmed that no user-controlled funds were compromised and that only two project-controlled addresses within its internal wallet infrastructure were affected. A comprehensive post-incident analysis document has not yet been made available.
These August security incidents occur against the backdrop of a previous Cosmos EVM vulnerability related to the ICS20 precompile component. A security bulletin published in March 2026 documented improper state management during nested execution contexts that enabled duplicate utilization of identical token balances within a single transaction operation.
That previous security flaw resulted in approximately $7 million in losses on the SagaEVM platform in January 2026. Whether the August attacks exploited the same code execution pathway or represent a distinct vulnerability remains unconfirmed.
Cosmos Labs has committed to publishing a comprehensive incident analysis once containment procedures are finalized. The forthcoming report is anticipated to identify the defective software component, enumerate affected software versions, and quantify total losses sustained across all impacted blockchain networks.
Pending the publication of official documentation, users are advised to continuously monitor authorized chain status dashboards and refrain from executing transactions through unverified or third-party interfaces.


