September 26, 2026

Cosmos Labs Tells EVM Chains to Halt Over Shared Bug

A vulnerability in the shared Cosmos EVM module has been exploited on three networks, prompting Cosmos Labs to urge affected chains to halt and patch immediately.
Cosmos Labs Tells EVM Chains to Halt Over Shared Bug

Cosmos Labs on Tuesday urged any public blockchain running its Cosmos EVM module below versions v0.6.2 or v0.7.2 to “immediately halt the blockchain and upgrade it to include the patches in those releases,” according toThe Defiant. The advisory was posted at 11:19 a.m. New York time and asked teams without established security contacts to email security@cosmoslabs.io for critical updates.

The Defiant reported that the warning applies to an unknown number of networks built on the shared open-source codebase. Three chains running it, MANTRA, TAC and KiiChain, were attacked between Aug. 20 and Aug. 22, and two remain frozen. Cosmos Labs has not published a formal security advisory detailing the underlying flaw, per the outlet.

KiiChain is the only affected network to disclose damage figures. Per The Defiant’s report of KiiChain’s Aug. 24 incident report, an attacker drained 148 million KII tokens from wallets on Aug. 22, repeating the same technique 18 times against different targets. That amount was worth roughly $9.7 million based on KII’s $0.0653 price at 21:00 UTC that day, according to CoinGecko data cited by the outlet. KiiChain halted its network at block 9,355,723, timestamped 22:50:58 UTC, and the chain remained stalled at that block 66 hours later, The Defiant said.

According to the incident report referenced by The Defiant, about 80.7 million KII, or 54.4% of the stolen funds, sits in attacker addresses frozen by the halt and will be redirected to recovery wallets upon restart. The remaining 67.6 million tokens were bridged to BNB Smart Chain via Hyperlane, where 64.6 million were sold on decentralized exchanges for approximately 1.61 million BUSD. The Defiant reported that two of the three underlying defects tied to the exploit remain unfixed upstream.

Based on reporting by thedefiant.io.

Leave a Reply

Your email address will not be published. Required fields are marked *