Cosmos Labs, the team that maintains the open-source Cosmos EVM module, has advised Cosmos EVM chains that are in contact with it to have their validators halt their networks while it responds to an ongoing security incident, according to a statement posted to its verified X account on August 24, 2026. The firm said the incident has affected users of the Cosmos EVM module but did not disclose the specific vulnerability, the chains involved, or any losses, and said it would publish an incident report once the situation is resolved.
The advisory broadens the response from individual chain halts to a warning directed at Cosmos EVM chains in contact with Cosmos Labs, as a cluster of Cosmos SDK networks that run Ethereum-compatible smart contracts through the shared Cosmos EVM stack have gone offline in quick succession.
What Cosmos Labs said
In its post, Cosmos Labs stated that, “An ongoing security incident has impacted users of the Cosmos EVM module.” The firm said its security and engineering teams had been responding proactively and had advised the Cosmos EVM chains in contact with it to request that their validators halt their chains. It thanked teams using Cosmos EVM for what it called a rapid response, said a full incident report would follow once the situation was resolved, and directed affected teams to contact it at its published security address, security@cosmoslabs.io.
The statement did not name the vulnerability, identifying which chains are affected, or quantifying any losses — details Cosmos Labs indicated would come in a later post-mortem. Readers should treat the scope of the incident as unconfirmed until that report or on-chain evidence establishes it.
A Widening Incident: MANTRA, KiiChain, and TAC
The advisory follows a run of halts across chains that share the Cosmos EVM codebase. The connections between them have not been formally confirmed by Cosmos Labs as parts of a single event, and the following is drawn from each project’s own disclosures and independent reporting.
MANTRA, an EVM Layer 1 focused on real-world assets, halted its mainnet on August 21 after detecting malicious activity it later traced to the Cosmos EVM module. Its last block before the halt was 17,449,398, recorded at roughly 23:13 UTC on August 20; the network resumed block production around 05:30 UTC on August 22 after deploying software version 8.4.0, an outage of about 30 hours. MANTRA said the incident affected two wallet addresses it controls and that, “No user funds were exploited.” The Crypto Times covered that halt as it happened.
KiiChain subsequently disclosed an exploit involving the shared Cosmos EVM module. According to its post-mortem, an attacker used the same technique 18 times and drained 148,326,583.15 KII before validators halted the network at block 9,355,723. KiiChain said the vulnerability was in the shared Cosmos EVM code rather than its own chain-specific code.
Additionally, TAC, an EVM network connected to TON, halted validator block production on August 22 after reporting that an exploited vulnerability affected its Cosmos EVM-based infrastructure. The network halted at block 24,671,475 after an attacker drained a single account. TAC said the vulnerability was rooted in the shared Cosmos EVM module.
The Risk of Shared Infrastructure
The common thread is the Cosmos EVM stack itself: the shared open-source software that lets Cosmos SDK chains run Ethereum-style smart contracts. That codebase has been the subject of at least one serious, separately documented flaw this year.
In January 2026, an attacker drained roughly $7 million from the Saga EVM network by using forged Inter-Blockchain Communication (IBC) messages to mint an uncollateralized stablecoin, then bridging the proceeds to Ethereum. Cosmos Labs documented the root cause in security advisory ASA-2026-002, which concerns the ICS20 precompile, the component that lets EVM smart contracts trigger cross-chain transfers over IBC. Per the advisory, incorrect state handling during nested EVM execution could allow the same token balance to be used more than once in a single transaction. Cosmos Labs said it identified 15 chains running the affected code, coordinated mitigations with ecosystem partners, and shipped a permanent fix in March 2026.
It has not been established that this week’s incident stems from the same ICS20 precompile flaw; neither Cosmos Labs’ latest advisory nor the affected chains have specified the vulnerability. What the earlier episode does establish is that a single weakness in the shared stack can expose many independent chains at once, the structural risk now back in focus.
A key point of accuracy: the Cosmos Hub and its ATOM token are a separate network. Cosmos EVM is an optional module used by certain application-specific chains, not by the Cosmos Hub itself, and nothing in the current disclosures indicates the Hub or ATOM has been exploited.
What to Watch
As of publication, the central facts of the incident remain undisclosed by the parties best placed to confirm them: Cosmos Labs has not named the vulnerability, the affected chains, or any losses. Loss figures and attacker activity circulating on social media should be treated as claims pending on-chain confirmation or an official post-mortem.
Readers should rely on concrete, verifiable next steps rather than forecasts: the incident report Cosmos Labs has said it will publish; whether additional Cosmos EVM chains announce halts; restart timelines and post-mortems from KiiChain and TAC; and on-chain confirmation of any loss figures and attacker addresses. The Crypto Times will update this story as those are established.
The Crypto Times has contacted the entities named in this report for comment as of 05:55 AM UTC.
Also read: Midnight Expands Zswap Infrastructure With Celestia Integration
