Loading market data...

Cosmos EVM Flaw Forces Halt on Three Chains After Drain Attacks

Cosmos EVM Flaw Forces Halt on Three Chains After Drain Attacks

Cosmos Labs has confirmed an ongoing security incident affecting the Cosmos EVM module, pushing three networks to halt block production. KiiChain, TAC, and MANTRA all disclosed impact from the same vulnerability, with attackers draining funds before validators stepped in.

MANTRA First to Disclose

MANTRA was the first chain to go public with the issue. The network stopped block production as a precaution after two MANTRA-managed wallets were affected. The team stressed that user balances were never touched. The vulnerability sat in the shared Cosmos-EVM module, and a fix shipped in version 8.4.0. That patch let MANTRA resume block production without further interruption.

KiiChain Hit 18 Times

KiiChain reported a more brutal series of events. An attacker repeated the same technique 18 times, draining 148,326,583.15 KII before validators halted the chain at block 9355723. KiiChain said the flaw lives in the shared Cosmos EVM module (cosmos/evm), not in KiiChain's own code. The network remains halted pending a coordinated binary upgrade at a predetermined block height. Notably, resumption won't require an on-chain governance proposal.

TAC's Single Account Drain

TAC halted at block 24,671,475 after an attacker drained a single account. The defect was traced to the same shared Cosmos EVM module, not to TAC-specific code. TAC has not yet detailed its recovery timeline, but the halt is in effect.

What's Known So Far

Cosmos Labs has not described the underlying cause of the vulnerability. The team plans to publish an incident report once the situation is fully resolved. The three networks disclosed the issue in quick succession, with MANTRA first, then KiiChain and TAC. For now, KiiChain remains halted while validators wait for the binary upgrade. TAC's status and the exact scope of the exploit remain open questions.