Cosmos Labs EVM bug halt: Urges Immediate Stop for Vulnerable Chains
Cosmos Labs issues an EVM bug halt advisory, urging vulnerable EVM chains to stop operations and upgrade after a multi-network drain of $9.7M.
Cosmos Labs issued an urgent advisory on August 25, 2026, announcing a Cosmos Labs EVM bug halt for any public blockchain that runs a Cosmos EVM module version earlier than v0.6.2 or v0.7.2. The recommendation followed coordinated attacks that drained three independent networks—MANTRA, TAC and KiiChain—between August 20 and August 22, resulting in a loss of roughly $9.7 million. The advisory was posted on X at 11:19 a.m. New York time and invited security contacts to email security@cosmoslabs.io for critical updates.
Context and Technical Roots
The Cosmos EVM module enables Ethereum-compatible smart contracts to execute on Cosmos-based chains. Its open-source nature means many projects adopt the same codebase, customizing only superficial parameters. The vulnerability exploited by the attacker resides in three upstream defects that must align to be triggered. The first is an underflow in the staking precompile when it writes a post-delegation balance back to the EVM state. The second and third defects remain undisclosed but are reported by KiiChain as still unfixed in the upstream repository. Because the affected chains run the module unmodified, the flaw is inherited directly from Cosmos Labs’ code rather than from any chain-specific implementation.
An ordinary wallet cannot reach the flaw because it cannot delegate more than its spendable balance, but a crafted transaction that repeatedly delegates and withdraws can force the underflow condition. The attacker repeated this technique 18 times across distinct targets on KiiChain, draining 148 million KII from wallets that had delegated stakes. The attack vector demonstrates how a seemingly innocuous staking precompile can become an attack surface when combined with downstream bugs.
Immediate Impact on Affected Networks
KiiChain halted its network at block 9,355,723 (timestamp 22:50:58 UTC on August 22) after detecting the breach. The halt immobilized roughly 80.7 million KII (~54.4 % of the stolen amount) pending a restart that will move the funds to recovery wallets. The remaining 67.6 million KII were already bridged to BNB Smart Chain via Hyperlane; 64.6 million of those were sold on decentralized exchanges for an estimated 1.61 million BUSD, while a final 3 million landed in a KuCoin deposit address, whose recoverability remains uncertain.
MANTRA and TAC, the other two impacted chains, have also frozen operations. Neither has publicly disclosed the precise financial loss, but both share the same vulnerable module version, suggesting comparable exposure. The lack of a formal security advisory from Cosmos Labs compounds operational uncertainty for these networks, as they must rely on ad-hoc communications to coordinate patches and recovery.
Implications for Market Structure
The incident underscores a systemic risk inherent in shared open-source modules across heterogeneous ecosystems. When a single upstream defect propagates, capital can be siphoned from multiple independent chains in a short window, creating a cascade of liquidity drains. For institutional investors, the episode raises red flags about exposure to EVM-compatible Cosmos chains that have not yet upgraded. The $9.7 million loss on KiiChain, while modest relative to total DeFi TVL, illustrates how quickly value can be extracted when a bug is exploitable at scale. A cross-chain TVL board shows that Cosmos-based EVM chains collectively hold less than 1 % of total TVL, but the concentration of capital in a few high-yield protocols amplifies the impact of any breach.
Furthermore, the bridge to BNB Smart Chain acted as a conduit for rapid liquidation, highlighting the importance of bridge risk management. Hyperlane transferred the stolen tokens within minutes, and the subsequent DEX sales on BNB Smart Chain demonstrate how inter-chain liquidity can accelerate fund outflows. Institutions that maintain exposure to BNB-based assets should monitor bridge activity for anomalous spikes, as they may signal downstream exploits.
Regulatory and Compliance Angles
While the attack does not appear to have triggered immediate regulatory enforcement, it aligns with broader supervisory concerns about cross-chain security and the adequacy of bug-bounty programs. The U.S. Securities and Exchange Commission has recently emphasized the need for robust security controls in platforms that facilitate token custody and bridging, as noted in its newsroom releases (the SEC). The absence of a formal advisory from Cosmos Labs could be viewed unfavorably by regulators assessing whether developers are meeting industry-standard disclosure practices. Moreover, the request for undisclosed security contacts suggests a gap in transparent communication channels, which could complicate compliance reporting for institutional participants.
Operational Consequences for Validators and Developers
Validators on the affected networks now face a dilemma: continue running a vulnerable client and risk further exploitation, or halt operations and incur downtime costs. The halt on KiiChain left the public node at block 9,355,723 for over 66 hours, effectively freezing transaction processing and staking rewards. For developers, the incident forces an immediate audit of any downstream dependencies on the Cosmos EVM module. Projects that have integrated the module without additional safeguards must allocate engineering resources to merge the v0.6.2 or v0.7.2 patches, test compatibility, and redeploy. The urgency is amplified by the fact that two of the three upstream defects remain unfixed, meaning that even patched versions may still carry residual risk until the upstream repository resolves all issues.
What to Watch Next
The next critical milestone will be the release of a comprehensive security advisory from Cosmos Labs that details the remaining upstream defects and outlines a migration path. Market participants should monitor the following signals:
- Patch Adoption Rate - The speed at which MANTRA, TAC, KiiChain and other downstream chains apply the v0.6.2/v0.7.2 patches. A lag could expose additional networks.
- Bridge Activity - Continued monitoring of Hyperlane and other bridges for abnormal token flows, especially from compromised chains to high-liquidity ecosystems like BNB Smart Chain.
- Regulatory Filings - Any SEC or other regulator statements referencing cross-chain security breaches may signal forthcoming guidance that could affect compliance requirements for custodians.
- Recovery Outcomes - The success of KiiChain’s recovery effort for the 80.7 million KII held in frozen addresses will set a precedent for how frozen assets are handled after a halt.
Institutions with exposure to Cosmos-based EVM chains should reassess their risk models, incorporate scenario analysis for similar multi-chain exploits, and consider diversifying across chains with more mature security governance.
Broader Implications for the Web3 Ecosystem
The Cosmos Labs episode illustrates the trade-off between rapid modular adoption and the security liabilities of shared codebases. As more projects seek to leverage the composability of Cosmos SDK and EVM compatibility, the pressure to maintain a clean upstream repository intensifies. A single underflow bug can cascade across dozens of independent economies, eroding confidence in cross-chain interoperability. This may accelerate calls for standardized security audit pipelines, mandatory bug-bounty disclosures, and perhaps a governance layer that enforces version pinning for critical modules.
From a product-strategy perspective, chains may begin to prioritize “security-first” forks of the EVM module, diverging from the upstream to mitigate systemic risk. This could fragment the ecosystem but also foster innovation in hardened execution environments. For custodians and institutional investors, the event reinforces the need for continuous code-level monitoring and the incorporation of upgrade-risk premiums into valuation models.
In sum, the Cosmos Labs EVM bug halt advisory is a stark reminder that shared open-source infrastructure, while powerful, demands rigorous governance and rapid response mechanisms. The $9.7 million drain, the freeze of multiple networks, and the lingering upstream defects together create a multi-dimensional risk profile that market participants cannot ignore.
Tags: security, EVM, Cosmos, cross-chain, institutional risk