Cosmos EVM Bug Exploited: Three Blockchains Halted After $9.7 Million Theft

Aug 26, 2026 08:47 Written by Yasir Arafat cosmos blockchain evm hack security
Cosmos EVM Bug Exploited: Three Blockchains Halted After $9.7 Million Theft

Cosmos EVM Module Bug Leads to Network Halts

Cosmos Labs has urged all public blockchains using versions of its Cosmos EVM module below v0.6.2 or v0.7.2 to immediately halt operations and upgrade. The warning comes after three blockchains—MANTRA, TAC, and KiiChain—were exploited due to a shared bug in the module. Two of the networks remain frozen as of August 25, 2026.

A blockchain is a digital ledger that records transactions across many computers. An EVM (Ethereum Virtual Machine) module allows blockchains to run smart contracts, which are self-executing agreements written in code. Cosmos Labs provides tools for building blockchains that can interact with each other.

Key Details of the Exploit

  • Three blockchains using the Cosmos EVM module were attacked between August 20 and August 22, 2026.
  • KiiChain lost 148 million KII tokens, worth approximately $9.7 million at the time.
  • The attacker exploited a combination of three bugs, including an underflow in the staking precompile.
  • Cosmos Labs released a patch on August 19 but did not issue a security advisory or notify affected chains privately.
  • Two of the three bugs remain unfixed in the upstream code, according to KiiChain.

How the Attack Worked

The attacker targeted a vulnerability in the Cosmos EVM module by creating a vesting account—a type of account that releases tokens over time—and exploiting it to drain funds. The attack involved delegating more tokens than the account could spend, causing an underflow that allowed the attacker to manipulate balances.

KiiChain stated that the attacker repeated the technique 18 times against different targets. The network halted at block 9,355,723 on August 22, and remains frozen. About 80.7 million KII tokens (54.4% of the stolen amount) are immobilized in attacker-controlled wallets and will be moved to recovery wallets once the chain restarts.

Response from Affected Networks

KiiChain accused Cosmos Labs of mishandling the disclosure, stating that the patch was released publicly without prior notice to affected chains. The team argued that this gave attackers time to exploit the bug before networks could upgrade. Cosmos Labs has not responded to these claims.

TAC, another affected network, halted on August 22 and remains offline. The team reported that 2.98 billion TAC tokens (about 62% of the circulating supply) were drained. MANTRA, the third network, resumed operations on August 22 after applying a patch but has not disclosed the amount lost.

What Is Confirmed

  • Three blockchains (MANTRA, TAC, and KiiChain) were exploited due to a bug in the Cosmos EVM module.
  • KiiChain lost 148 million KII tokens, worth roughly $9.7 million.
  • Cosmos Labs released patches (v0.6.2 and v0.7.2) but did not issue a security advisory or notify chains privately.
  • Two of the three bugs remain unfixed in the upstream code, per KiiChain’s report.
  • TAC and KiiChain remain halted as of August 25, 2026.

What Remains Unclear

  • Cosmos Labs has not confirmed whether the two remaining bugs will be fixed or when.
  • It is unknown how many other blockchains using the Cosmos EVM module are at risk.
  • KiiChain’s claim that Cosmos Labs mishandled the disclosure has not been addressed by Cosmos Labs.
  • The total impact on TAC and MANTRA has not been fully disclosed.

Why This Matters for Crypto Users

This incident highlights risks in shared blockchain code. When a bug exists in a widely used module, multiple networks can be affected simultaneously. Users of blockchains running the Cosmos EVM module should check for official updates from their network teams.

The exploit also raises concerns about responsible disclosure. KiiChain argued that Cosmos Labs’ decision to release the patch publicly without notifying affected chains first allowed attackers to exploit the bug before networks could respond.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!