Cosmos Labs confirmed an ongoing security incident in the Cosmos EVM module on August 25, urging affected chains to have validators halt block production while engineers investigate. The bug has already hit three networks: MANTRA, KiiChain, and TAC, with KiiChain losing over 148 million KII and TAC losing roughly $7.5 million in a separate exploit.
How a Cosmos EVM Flaw Triggered Validator Halts
The Cosmos EVM module lets Cosmos SDK-based blockchains run Ethereum-compatible smart contracts, so networks like MANTRA, KiiChain, and TAC can plug into the same developer tools and dApps that Ethereum supports instead of building that compatibility themselves.
That shared foundation makes the module useful, but it also means a single flaw inside it can surface on every chain that runs it, instead of staying contained to one project’s code.
Cosmos Labs said its security and engineering teams are actively responding and have asked affected chains to halt their validators as a precaution while they investigate.
The organization has not disclosed the specific vulnerability or the combined funds at risk across the three networks, and it said a full incident report will follow once the investigation is complete.
How MANTRA, KiiChain, and TAC Were Affected
MANTRA was the first to react, halting its Layer 1 chain on August 20 after detecting suspicious activity tied to two MANTRA-managed wallets. The team traced the issue to the shared Cosmos EVM module, deployed patched software version 8.4.0, and resumed block production about 30 hours later without a rollback. MANTRA said no user, exchange, or partner funds were affected.
KiiChain was hit harder. According to FinanceFeeds, an attacker repeated the same exploit 18 times on August 22, draining 148,326,583.15 KII before validators halted the chain at block 9,355,723.
The KiiChain team said the flaw sits in the shared Cosmos EVM code it runs unmodified, and the network plans to resume through a coordinated binary upgrade at a set block height rather than an on-chain governance vote.
TAC, a TON-connected EVM network, halted the same day at block 24,671,475 after an attacker accessed and drained a single account through the Cosmos EVM precompile layer. TAC also attributed the defect to the shared module rather than its own code, and later reports pointed to a loss of roughly 29.86 billion TAC, worth around $7.5 million, though that figure has not been confirmed in an official postmortem.
What This Means for Cosmos Ecosystem Users
Any project built on Cosmos EVM now carries some exposure until Cosmos Labs finishes its review, so users and validators on other Cosmos SDK chains should watch for official guidance before assuming their network is unaffected. We’ll keep following this story on our news hub as more chains confirm their status.
What to Watch Next
KiiChain’s coordinated binary upgrade, set to activate at a predetermined block height across all validators simultaneously, is the most concrete near-term milestone: it will show whether the shared Cosmos EVM patch actually closes the exploit path attackers used against KII. Beyond that, Cosmos Labs’ promised technical postmortem should clarify whether other Cosmos EVM chains beyond MANTRA, KiiChain, and TAC carry the same exposure.
What this means for you: A network “halting” simply means validators paused adding new transactions on purpose, so it’s a safety measure, not a sign the chain has collapsed. If you hold assets on a Cosmos EVM chain, check that project’s official announcements before transacting again, and wait for confirmation that the module has been patched.

