Cosmos Labs has publicly warned of an active security incident tied to its shared Cosmos EVM module, an open-source component that lets Cosmos SDK-based chains support Ethereum Virtual Machine-compatible smart contracts. Because the module is reused across multiple independent networks, a single vulnerability can create simultaneous exposure. On August 24, 2026, Cosmos Labs advised affected Cosmos EVM chains in contact with its team to ask validators to halt block production while security and engineering teams work to contain the issue.
The advisory followed a series of individual disclosures. MANTRA, a real-world asset-focused chain, detected unauthorized activity around August 20–21, paused operations, and later identified the root cause as the Cosmos EVM module. It applied a software update and resumed block production after roughly 30 hours, stating only certain internal wallets were involved and ordinary user balances remained unaffected. KiiChain suffered a broader impact: an attacker repeated the same technique across 18 instances on August 22, draining about 148.3 million KII tokens from various wallets before validators halted the chain. The project linked the exploit to issues with vesting accounts, staking operations, and balance handling. TAC also suspended operations on August 22 after an attacker emptied a single account by exploiting a weakness in a Cosmos EVM precompile.
Blockchain analytics firm Bubblemaps traced part of the activity involving Nesa Chain. An attacker used a wallet identified as 0x9AE7 to buy $250,000 worth of NES tokens, moved them to Nesa Chain, inflated the balance roughly 200 times, and bridged the tokens back, totaling about $50 million in NES. However, when attempting to sell on decentralized exchanges, extreme slippage consumed nearly the entire position. The hacker’s net gain amounted to only about $60,000. Bubblemaps connected the funds through eight wallets to an address funded via the privacy coin Monero.
Cosmos Labs has instructed any network running a module version below v0.6.2 or v0.7.2 to halt and apply the corresponding patches. The four networks confirming issues were KiiChain, MANTRA, TAC, and Nesa. A detailed post-mortem from Cosmos Labs is still pending, and chains that halted are awaiting guidance on safe restart procedures. The incident underscores the systemic risks of shared modular blockchain infrastructure: it accelerates development but means a single upstream defect can propagate across multiple networks.