Key Points
- Cosmos Labs issued urgent guidance on Aug. 25 for affected Cosmos EVM-based chains to immediately halt validator operations amid an ongoing security breach.
- Attackers successfully extracted 148,326,583.15 KII tokens from KiiChain through 18 consecutive exploit attempts executed on Aug. 22.
- TAC blockchain suspended operations at block height 24,671 following the drainage of one account through a Cosmos EVM precompile vulnerability.
- MANTRA network restored block production following approximately 30 hours of downtime, confirming no user fund losses occurred.
- Full vulnerability details, comprehensive list of impacted networks, and aggregate loss calculations remain undisclosed by Cosmos Labs.
Several blockchain platforms utilizing the Cosmos EVM software infrastructure were compelled to cease operations during the final week of August 2026 following the discovery of an active security compromise affecting the shared module framework by Cosmos Labs.
The Cosmos EVM framework functions as an integration layer enabling Cosmos SDK-based blockchains to achieve Ethereum Virtual Machine compatibility. Due to its shared architecture, any security weakness within this module can cascade across all implementing networks.
According to Cosmos Labs, both security specialists and engineering personnel initiated immediate response protocols. The organization recommended that vulnerable chains instruct their validator operators to temporarily suspend block generation pending the development of security patches.
KiiChain and TAC Experience Significant Asset Drains
KiiChain’s official disclosure verified that malicious actors successfully extracted 148,326,583.15 KII tokens from user wallets on Aug. 22. The perpetrator executed the exploit methodology across 18 separate instances before network validators implemented an emergency halt at block height 9,355,723.
According to KiiChain’s analysis, the attack vector exploited weaknesses in the interaction between vesting account mechanisms, staking functionalities, and balance management protocols within the Cosmos EVM infrastructure. A portion of the compromised assets was subsequently transferred to BNB Smart Chain utilizing the Hyperlane cross-chain bridge protocol.
TAC blockchain similarly disclosed a security breach occurring on Aug. 22. The attacker leveraged a vulnerability within the Cosmos EVM precompile architecture to completely drain a single account before network validators executed an emergency shutdown at block 24,671.
Both affected projects verified unauthorized token transfers from their respective networks. Cosmos Labs has refrained from publishing consolidated loss estimates or confirming whether a single threat actor orchestrated both compromises.
MANTRA Network Resumes Following Extended Suspension
The MANTRA blockchain implemented network suspension protocols on Aug. 20 upon identifying anomalous transaction patterns affecting two internally-managed wallet addresses. Development team analysis attributed the irregularities to vulnerabilities within their Cosmos EVM module implementation.
Following the deployment of patched software releases, MANTRA orchestrated a coordinated validator network restart procedure. Block production resumed after approximately 30 hours of downtime, with operations recommencing from a state snapshot captured at block 17,449,398 while maintaining the complete historical chain state without rollback.
MANTRA’s official statement confirmed zero impact to end-user fund security, noting that both affected wallet addresses were components of the project’s internal treasury management infrastructure. A comprehensive technical post-mortem analysis remains forthcoming.
These August security incidents represent the second major vulnerability discovery affecting Cosmos EVM infrastructure. A previous security flaw involving the ICS20 precompile component was documented in a March 2026 security bulletin, which detailed improper state management during nested execution contexts enabling duplicate utilization of identical token balances within single transaction scopes.
That previous vulnerability resulted in approximately $7 million in losses on the SagaEVM network during January 2026. Confirmation regarding whether the August attack vectors exploited identical code pathways or represented distinct security weaknesses remains pending.
Cosmos Labs has committed to publishing comprehensive incident documentation following complete containment of the security situation. The anticipated report is expected to specify the compromised software components, affected version releases, and aggregate financial losses spanning all impacted blockchain networks.
Pending official incident report publication, users are advised to actively monitor authenticated chain status communication channels and refrain from executing transactions through unverified third-party interfaces.





