Cosmos Labs urges EVM chains to halt after 148,326,583.15 KII drained

Cosmos Labs urged Cosmos EVM chains in contact with the company to request validator halts on Aug. 25 as its security and engineering teams responded to an incident affecting users of the shared software module. The company did not initially identify the vulnerability, affected chains or total losses, and said it would publish an incident report after the situation was resolved. KiiChain reported that an attacker drained 148,326,583.15 KII on Aug. 22 through a technique repeated 18 times before validators stopped the network at block 9,355,723. KiiChain linked the exploit to a Cosmos EVM vulnerability involving vesting accounts, staking operations and balance handling, and said some assets were bridged to BNB Smart Chain through Hyperlane. TAC separately reported an Aug. 22 exploit involving the Cosmos EVM precompile layer and halted at block 24,671. MANTRA stopped its network on Aug. 20 after activity involving two project-managed wallets, deployed an updated release and resumed after roughly 30 hours from a snapshot at block 17,449,398 without rolling back recorded state. MANTRA said no user funds were affected, while its full post-mortem and asset accounting remain unpublished. Cosmos Labs has not confirmed that the incidents share one vulnerability, identified every chain asked to halt or published aggregate losses. The response underscores the risk of a common software module: a flaw in a shared component can affect otherwise independent Cosmos SDK networks running vulnerable versions or configurations. The immediate priorities are identifying vulnerable deployments, distributing a tested patch and coordinating validator upgrades before chains resume block production.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.