A shared software module turned a single accounting bug into a six-chain exploit, forcing MANTRA, KiiChain and TAC to halt block production.
A shared software module turned a single accounting bug into a six-chain exploit, forcing MANTRA, KiiChain and TAC to halt block production.

A flaw in the shared Cosmos EVM module drained about $5.72 million across six blockchains, forcing three networks to halt.
Cosmos Labs, which published a post-mortem Aug. 28, said the flaw was reported through its bug bounty program April 25 but initially assessed as posing no risk to production funds.
Attackers converted about $2.87 million through decentralized exchanges and $2.85 million through centralized venues, whose accounts have been frozen, Cosmos Labs said. MANTRA, KiiChain and TAC were named among the six affected networks.
The incident exposed a shared-dependency risk across the Cosmos ecosystem, which spans more than 115 public chains. Cosmos Labs said it contacted 40 networks and discovered 11 Cosmos EVM deployments it had not previously known about.
The sequence explains why the case drew scrutiny beyond the dollar figure. Cosmos Labs received the initial report April 25 and, after testing, concluded the bug affected six-decimal chains while known production networks used 18 decimals. A fix merged into the main branch May 15 as a silent public patch, without a security-critical label. On Aug. 13 the team confirmed all Cosmos EVM chains were vulnerable regardless of decimal configuration.
The corrected releases arrived Aug. 19. A public pull request describing the attack route became accessible Aug. 20 at 07:16 UTC, and the first unauthorized transaction ran on MANTRA the same day at 19:06 UTC. The first private notification to affected chains went out Aug. 21 at 03:36 UTC, about two hours after MANTRA reported the incident. Cosmos Labs advised validators to halt Aug. 24.
MANTRA halted Aug. 21 at block 17,449,398 and resumed Aug. 22 on version 8.4.0. An unprivileged wallet moved about 720.9 million tokens from two addresses — roughly 600 million from a burn address and 120.9 million from a legacy genesis-era multisig — valued at about $3.6 million at the pre-incident price. MANTRA fell to an all-time low after the attack before rebounding about 14 percent to roughly $0.004744.
KiiChain halted at block 9,355,723 after the technique was applied 18 times in succession. The chain named 148,326,583.15 KII as drained, with a face value near $9 million, while selling brought in about $1.6 million. TAC stopped Aug. 22 at block 24,671,475 after an account was emptied. Both teams traced the cause to the shared Cosmos EVM code.
The gap between nominal value and realized proceeds explains why damage figures in circulation range from under $2 million to over $9 million. The $5.72 million figure reflects what attackers actually converted, not the face value of drained tokens.
The programming error is undisputed; the order of disclosure is not. A silent patch works only if operators running the code know beforehand they need to act. KiiChain argued in its own post-mortem that publishing a security fix openly before affected chains are privately informed passes the vulnerability to anyone reading the commit. Cosmos Labs acknowledged it skipped the private distribution step its own bounty rules call for when a vulnerability carries network-wide risk.
Cosmos Labs said it will broaden vulnerability triage beyond the reporter's proof of concept, expand its security contact network, and set clearer standards for when to recommend a halt over a coordinated upgrade. An external audit of its operational security practices is planned.
For holders of OM, KII, TAC or other tokens on a Cosmos EVM chain, three states must be kept apart. A block explorer shows whether the chain is still producing blocks. A wallet check shows whether an address still holds the expected balance. An exchange status page shows whether deposits and withdrawals are open. A halted chain can carry unchanged balances, and a running chain can sit behind a frozen exchange gateway.
The case is less about a single flaw than about how quickly security information reaches the operators of shared infrastructure. Eleven Cosmos EVM deployments were not registered in Cosmos Labs' security channels, meaning they could not have been warned privately in an emergency. For a holder, a chain's security depends not only on its own team but on the external building blocks it adopts and how fast it applies updates.
This article is for informational purposes only and does not constitute investment advice.