Cosmos Labs urges immediate halt for Cosmos EVM chains below patched versions after exploits

Cosmos Labs recommended that public blockchains running its Cosmos EVM module below v0.6.2 or v0.7.2 immediately halt and upgrade after attackers compromised MANTRA, TAC and KiiChain between Aug. 20 and Aug. 22, with Nesa later suspending operations over related malicious activity. KiiChain said delayed warnings allowed exposure to continue and reported that 148,326,583.15 KII was drained across 18 transactions on Aug. 22 before validators halted the chain, with roughly 67.6 million KII bridged through Hyperlane to BNB Smart Chain. On-chain analysis platform Bubblemaps said the main Nesa attacker address 0x9AE7 bought NES, bridged it to Nesa Chain, used a shared-module balance vulnerability to inflate the position 200 times, then bridged roughly $50 million of NES back to Ethereum. Initial funding came from Monero; tokens were split across wallets, swapped for ETH on decentralized exchanges and deposited to centralized venues. Rapid liquidity withdrawal produced extreme slippage, so an attack costing about $255,000 realized only about $315,000 and a net profit of roughly $60,000. Bubblemaps said another Cosmos EVM chain suffered a similar roughly $1.4 million attack a day earlier, but funding sources and methods suggest a different attacker. NES once fell about 90% and later rebounded sharply, which the team linked mainly to post-attack DEX-CEX price-gap arbitrage. TAC remained halted after a large internal move of TAC without new minting, while MANTRA restarted on a patched binary.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.