Cosmos Labs has confirmed an ongoing security incident affecting the Cosmos EVM module, pushing three networks to halt block production. KiiChain, TAC, and MANTRA all disclosed impact from the same vulnerability, with attackers draining funds before validators stepped in.
MANTRA First to Disclose
MANTRA was the first chain to go public with the issue. The network stopped block production as a precaution after two MANTRA-managed wallets were affected. The team stressed that user balances were never touched. The vulnerability sat in the shared Cosmos-EVM module, and a fix shipped in version 8.4.0. That patch let MANTRA resume block production without further interruption.
KiiChain Hit 18 Times
KiiChain reported a more brutal series of events. An attacker repeated the same technique 18 times, draining 148,326,583.15 KII before validators halted the chain at block 9355723. KiiChain said the flaw lives in the shared Cosmos EVM module (cosmos/evm), not in KiiChain's own code. The network remains halted pending a coordinated binary upgrade at a predetermined block height. Notably, resumption won't require an on-chain governance proposal.
TAC's Single Account Drain
TAC halted at block 24,671,475 after an attacker drained a single account. The defect was traced to the same shared Cosmos EVM module, not to TAC-specific code. TAC has not yet detailed its recovery timeline, but the halt is in effect.
What's Known So Far
Cosmos Labs has not described the underlying cause of the vulnerability. The team plans to publish an incident report once the situation is fully resolved. The three networks disclosed the issue in quick succession, with MANTRA first, then KiiChain and TAC. For now, KiiChain remains halted while validators wait for the binary upgrade. TAC's status and the exact scope of the exploit remain open questions.




