Newsroom
25 August, 2026 / News / AI / Tags: cosmos, module, kiichain, evm, mantra

Three Cosmos EVM networks report exploits tied to a shared module as the developer issues an emergency advisory and promises a full incident report
Cosmos Labs instructed every Cosmos EVM chain in contact with the company to request that validators halt block production on August 24, 2026, citing an ongoing security incident affecting users of the module. The software enables Cosmos SDK blockchains to support Ethereum-style smart contracts. The advisory followed separate disclosures from MANTRA, KiiChain and TAC, each of which linked unauthorized activity to the shared component.
Cosmos Labs stated that its security and engineering teams were responding and would publish an incident report once the situation is resolved. The company has not named the vulnerability, listed every affected network or provided a restart timeline.
MANTRA stopped block production on August 20 after detecting activity involving two project-managed wallets. The team attributed the issue to a vulnerability in an upstream dependency within the Cosmos EVM module. User balances remained unaffected, according to the network.
Validators resumed operations roughly 30 hours later on a patched release identified as version 8.4.0. The chain restarted from a snapshot without rolling back state. During the outage the MANTRA token reached an all-time low of $0.0041. A full post-mortem has not yet been released.
KiiChain disclosed that an attacker executed the same technique 18 times on August 22, moving 148,326,583.15 KII tokens out of the network through the Hyperlane bridge to BNB Smart Chain. Validators halted the chain at block 9,355,723.
The project stated the vulnerability resides in the shared Cosmos EVM module rather than in KiiChain-specific code and involves vesting accounts, staking operations and balance handling. Hyperlane served only as the transfer route. The network remains halted pending a coordinated binary upgrade at a predetermined block height that will not require an on-chain governance vote.
| Chain | Halt Date | Status | Reported Impact |
|---|---|---|---|
| MANTRA | August 20 | Resumed after ~30 hours | Two internal wallets; no user funds |
| KiiChain | August 22 | Still halted | 148.3 million KII drained in 18 transactions |
| TAC | August 22 | Still halted | One account drained; TAC token supply affected |
TAC validators paused the network at block 24,671,475 on August 22 after an attacker drained one account. The team said the exploited vulnerability sits in the Cosmos-based EVM side of the chain and affects only the TAC token supply. Like KiiChain, TAC attributed the defect to the shared module rather than project-specific code.
No aggregate loss figure across the three networks has been confirmed by Cosmos Labs.
The August events follow a January incident in which an attacker used forged cross-chain messages against the ICS20 precompile in the same module, draining approximately $7 million from Saga. Cosmos Labs shipped a fix in March under security advisory GHSA-54gx-3cgr-7mfm and listed 15 chains, including MANTRA, as having remediated the issue.
Whether the latest exploits reuse that exact code path, a related weakness or a separate flaw remains undetermined until the promised incident report appears. Cosmos Labs has directed teams with questions to its security contact rather than public channels and has withheld software version numbers and mitigation steps while investigation continues.
As of August 25, 2026, no public restart schedule exists for chains still under the advisory. Users and validators are advised to monitor official status channels from the affected projects and Cosmos Labs for further updates.









