Key Takeaways: Cosmos Labs warned validators to halt block production Aug. 24 after a third exploit hit its EVM module in 2026.
Key Takeaways: Cosmos Labs warned validators to halt block production Aug. 24 after a third exploit hit its EVM module in 2026.

Cosmos Labs urged chains using its EVM module to halt operations Aug. 24 after a third exploit wave hit the shared codebase in 2026.
Cosmos Labs said in its Aug. 24 advisory that affected validators should stop their networks to prevent further damage, with a full incident report planned once the situation is contained.
The warning follows a breach at MANTRA Chain between Aug. 20 and 22 that forced a 30-hour mainnet halt before version 8.4.0 restored operations, and an attack on TAC on Aug. 22 that exploited precompile-layer vulnerabilities to move funds without minting new tokens. Both incidents trace to ASA-2026-002, a critical flaw disclosed in March involving the ICS20 precompile's incorrect state handling during nested EVM execution.
Cosmos Labs has not disclosed the full list of affected chains or the total value at risk. The advisory effectively freezes block production across the ecosystem until further guidance, raising questions about whether the March patch was incomplete or attackers found new pathways through related code.
The January SagaEVM exploit drained an estimated $7 million and affected 15 chains using the module, though only one was ultimately exploited. MANTRA's native token fell 18.5 percent to a record low of $0.004126 during the August incident, while trading volume surged nearly 600 percent to roughly $24 million, CoinGecko data shows.
MANTRA resumed block production at approximately 5:30 a.m. UTC on Aug. 22 after deploying version 8.4.0, which contained the security fix and additional protective measures. The network restarted at block height 17,449,398 without a state rollback, and the project confirmed that no user funds were exploited — the two affected addresses belonged to MANTRA's internal wallet infrastructure.
The recurring breaches highlight systemic risk in shared infrastructure. Cosmos EVM is a plug-and-play layer that gives Cosmos SDK chains Ethereum compatibility, meaning a single vulnerability can cascade across multiple networks. The timing of the Aug. 24 warning — two days after the TAC attack — suggests attackers may have generalized their exploit across chains sharing the same codebase.
Cosmos Labs plans to release a full incident report once the situation is contained. Until then, affected chains remain offline, and the total financial impact across the ecosystem is not yet disclosed.
This article is for informational purposes only and does not constitute investment advice.