Points of Focus
- Cosmos Labs urged Cosmos EVM chains in contact with it to halt validators as teams responded to an ongoing security incident.
- KiiChain saw 148.3M KII drained across 18 attacks before halting at block 9,355,723.
- TAC reported a 2.99B TAC transfer, while MANTRA restarted after patching the module.
Cosmos Labs urged Cosmos EVM chains in contact with it to halt block production after KiiChain, TAC and MANTRA disclosed security incidents tied to the shared module.
The warning points to a broader risk across networks using Cosmos EVM, though Cosmos Labs hasn’t confirmed that all three incidents followed the same exploit path.
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…
— Cosmos Labs (@cosmoslabs_io) August 24, 2026
KiiChain sees 148M KII drained across 18 attacks
KiiChain reported the largest disclosed token drain among the three networks. The attacker repeated the technique 18 times on Aug. 22, moving 148,326,583.15 KII before validators stopped the network at block 9,355,723.
KiiChain traced the attack to balance handling involving vesting accounts and staking in the shared Cosmos EVM module. About 80.7 million KII, or 54.4% of the drained amount, remained on KiiChain and is planned for transfer to recovery wallets during the network upgrade. Another 67.6 million KII crossed to BNB Smart Chain, where most was sold, while 3 million KII reached a KuCoin deposit address.
TAC and MANTRA report different levels of impact
TAC halted at block 24,671,475 on Aug. 22 after an attacker exploited the Cosmos EVM precompile layer and transferred 2,985,651,403 TAC from a single account. TAC said no new tokens were minted, leaving total supply unchanged, and that other assets on the network weren’t affected.
On August 22 an attacker exploited a vulnerability in the Cosmos EVM precompile layer and drained a single account on TAC. We halted the chain at block 24,671,475 to stop it. The defect is not in TAC-specific code. It sits in the shared Cosmos EVM module, and several other chains…
— TAC (🫰,✨️) (@TacBuild) August 24, 2026
MANTRA had halted earlier after activity affected two project-managed wallets. The chain resumed block production on Aug. 22 after deploying version 8.4.0, with the team saying the Cosmos EVM vulnerability had been fixed and no user funds were affected.
MANTRA Chain is producing blocks again.
The vulnerability in the Cosmos-EVM module has been fixed, the network has resumed, and no user funds were affected.
Thank you to everyone for your patience throughout the incident.
Review the full history of incident status updates… pic.twitter.com/IDVpw7H7Tp
— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain) August 22, 2026
Cosmos Labs said in an Aug. 24 post that its security and engineering teams were responding to the incident and had advised Cosmos EVM chains in contact with it to request validator halts.
Three is the number of networks with public disclosures so far, not a confirmed count of every chain exposed. Cosmos Labs hasn’t published a full affected-chain list, aggregate losses or a root cause tying all three incidents together.
Shared Cosmos EVM code raises multi-chain risk
Cosmos EVM is an open-source Cosmos SDK module that gives independent chains Ethereum Virtual Machine compatibility. Because multiple networks can run the same component, a flaw in shared code can affect more than one chain.
A separate critical ICS20 precompile flaw disclosed by Cosmos Labs in March shows that risk isn’t theoretical. Cosmos Labs identified 15 chains running code containing that issue. Six didn’t have the affected feature enabled, the remaining chains mitigated the flaw before exploitation, and one network suffered an estimated $7 million loss, according to the GitHub advisory.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


