Cosmos Labs told EVM chains to halt block production on Aug. 25 after a shared module flaw drained 148 million KII from KiiChain.
Cosmos Labs told EVM chains to halt block production on Aug. 25 after a shared module flaw drained 148 million KII from KiiChain.

Cosmos Labs on Aug. 25 urged EVM chains to halt validators after a shared module flaw drained 148.3 million KII from KiiChain, MANTRA and TAC.
"An ongoing security incident has impacted users of the Cosmos EVM module," Cosmos Labs said in a statement on Aug. 24, adding that its security and engineering teams were "proactively responding" and had advised affected chains to request validator halts.
KiiChain said an attacker drained 148,326,583.15 KII across 18 wallets on Aug. 22 before validators stopped the network at block 9,355,723. The team linked the attack to a Cosmos EVM vulnerability involving vesting accounts, staking operations and balance handling, and said 67.6 million KII was bridged to BNB Smart Chain through Hyperlane, with 64.6 million sold for BUSD/USDT on PancakeSwap. TAC separately said an exploit of the Cosmos EVM precompile layer drained one account, halting the chain at block 24,671.
Cosmos EVM is a shared software stack that lets Cosmos SDK chains run Ethereum-compatible smart contracts, so a flaw in one module exposes every network running affected versions. Cosmos Labs has not disclosed the underlying vulnerability, affected chains or total losses, and promised an incident report after the situation is resolved.
KiiChain's 18-round drain leaves 54% recoverable
KiiChain's incident report said the attacker repeated the technique 18 times, hitting a different wallet each time, before the team spotted the activity and froze the chain at 22:50:58 UTC. More than half the stolen tokens never left the network: 80,728,575.06 KII, or 54.4 percent, remains frozen in attacker wallets and is recoverable once the chain restarts with a fix.
The portion that reached BNB Smart Chain is largely gone. The attacker sold 64,597,997.87 KII for BUSD/USDT through a PancakeSwap pool, realizing about 1.6 million BUSD, and sent 3 million KII to a KuCoin deposit address, where a freeze was requested. KiiChain said it would cap the Hyperlane bridge at 10 million KII per rolling 24 hours to slow any future exploit.
A public fix sat for two days before the halt
The KiiChain report said Cosmos Labs pushed a fix for the underflow bug to a public code repository on Aug. 19 without flagging it as urgent, then told affected chains on Aug. 21 buried inside routine updates. MANTRA was hit that day, followed by TAC and KiiChain on Aug. 22, before Cosmos Labs recommended halts.
MANTRA stopped its network on Aug. 20 after detecting activity involving two project-managed wallets, isolated the incident to its Cosmos EVM module, and resumed block production after a roughly 30-hour halt from a snapshot at block 17,449,398. The team said no user funds were affected, though its full post-mortem remains unpublished.
The incidents follow an earlier Cosmos EVM flaw involving the ICS20 precompile, which a March advisory said allowed the same token balance to be used repeatedly within one transaction. That issue caused an estimated $7 million loss on SagaEVM in January.
Cosmos Labs' promised report should identify the faulty component, affected versions, exploitation timeline and total losses, and confirm whether MANTRA, TAC and KiiChain were compromised through the same code path. Until it appears, other teams using Cosmos EVM may keep networks halted or disable affected functionality, and users should rely on official chain status pages and avoid transactions through unverified interfaces.
This article is for informational purposes only and does not constitute investment advice.