A security vulnerability in the shared Cosmos EVM module has led to a series of exploits on multiple networks, including KiiChain, MANTRA, and TAC. According to KiiChain, delayed warnings allowed an attacker to drain over 148 million KII tokens on August 22 before the network was halted. The root cause was identified as three upstream defects, including an underflow in the staking precompile. Cosmos Labs has urged affected networks to halt operations but has not yet confirmed a single common flaw. A security fix was made public on August 19, but KiiChain stated that affected networks were not given advance notice or a clear flag that it was critical.
A security vulnerability in the shared Cosmos EVM module has led to a series of exploits on multiple networks. Cosmos Labs has urged affected networks in contact with its team to halt operations amid the ongoing incident.
KiiChain reported that an attacker drained 148,326,583.15 KII from wallets on August 22, repeating the same technique 18 times against different targets. The chain detected the activity and halted at block 9,355,723, stopping further theft and freezing remaining funds. According to KiiChain, the root cause was identified, reproduced, and fixed.
The vulnerability was in the shared Cosmos EVM module, not KiiChain-specific code. Three upstream defects combined to enable the attack, including an underflow in the staking precompile when it writes a post-delegation balance back to the EVM. KiiChain stated that “the same class of vulnerability affected Cosmos EVM chains with vesting accounts enabled.”
A security fix for one of the three flaws was made public on August 19. However, KiiChain said affected networks were not given advance notice, and the release was not clearly flagged as a critical security update. When communication reached affected chains two days later, the fix was included with unrelated issues already being handled privately. MANTRA had already been exploited by then.
TAC separately stated that an attacker exploited a vulnerability in the Cosmos EVM precompile layer on the same day, draining a single account. The chain was halted, and it was said that 2,985,651,403 TAC was moved between accounts, though no new tokens were created.
MANTRA halted its Layer 1 network last week for about 30 hours as a precaution. The project later said it had identified the root cause and that no user funds were exploited. MANTRA stated the incident affected two wallet addresses, and the network resumed operations after a patch was deployed.
