In major Crypto news today, Cosmos Labs confirmed an active security incident on August 24, 2026, and asked every EVM chain in contact with the company to request validator halts while its security and engineering teams investigate.
The disclosure came after three separate networks running the same EVM module, KiiChain, TAC, and MANTRA, had already suffered unauthorized fund movements earlier in the month.
Cosmos Labs has not named every impacted chain, confirmed one shared root cause, or released a total loss figure. The company said a full incident report will follow once the situation is resolved.
As of August 25, 2026, no public restart timetable exists for chains still waiting on guidance, and the official Cosmos Labs statement remains the only confirmed source on the matter.
Key facts so far:
Cosmos Labs issued its Labs security incident advisory on August 24, 2026
KiiChain confirmed 148,326,583.15 KII drained across 18 repeated attacks on August 22
TAC halted block production after one account was drained on August 22
MANTRA resumed operations after a roughly 30-hour shutdown that began August 20
No aggregate loss figure or shared root cause has been confirmed publicly
Cosmos EVM is shared infrastructure that lets SDK chains run Ethereum-style smart contracts. A flaw in one shared component can therefore expose every independent chain running the same code.
In its statement, Labs said its teams were "proactively responding" and had asked contacted chains to coordinate with validators to stop block production, the standard emergency response for a EVM module vulnerability on proof-of-stake networks.
The company deliberately withheld the software version, mitigation steps, and a restart schedule, a common practice to avoid revealing exploitable detail before every exposed chain is patched.
Teams with questions were directed to Labs' security email rather than a public channel.
The alert was also flagged in real time by trading commentary accounts, WuBlockchain also covered this incident, tracking the spread across affected chains in its own reporting thread.
KiiChain disclosed the largest confirmed loss tied to the EVM exploit pattern so far.
According to KiiChain's official incident report, an attacker repeated the same technique 18 times on August 22 before validators halted the network.
Detail | Figure |
Tokens drained | 148,326,583.15 KII |
Attack repetitions | 18 |
Halt block | 9,355,723 |
Bridge used | Hyperlane to BNB Smart Chain |
KiiChain linked the KiiChain KII hack to a vulnerability touching vesting accounts, staking operations, and balance handling inside the Cosmos EVM module. Hyperlane itself was not named as the flawed component, only the route used to move assets off-chain.
TAC reported a narrower incident. Its team said an attacker exploited a weakness in the EVM precompile layer, draining one account before validators halted the chain. Full details are in TAC's official update. 
Chain | Halt Date | Duration/Status | Impact Disclosed |
MANTRA | Aug 20 | ~30 hours, resumed | 2 internal wallets, no user funds |
KiiChain | Aug 22 | Still under review | 148.3M KII drained |
TAC | Aug 22 | Still halted | 1 account drained |
The MANTRA chain halt began August 20 after activity involving two project-managed wallets.
Per MANTRA's official update, the team isolated the cause to its EVM module, shipped patch v8.4.0, and restarted roughly 30 hours later without a chain rollback. MANTRA said no user funds were exploited, though a full post-mortem remains unpublished.
Users can monitor the network's current uptime on the official MANTRA Status Page. MANTRA stated no user funds were exploited, though a full post-mortem remains unpublished.
The Cosmos EVM security incident has now touched three separate networks in under a week, turning what looked like isolated exploits into a shared infrastructure problem.
MANTRA has recovered, but TAC and other contacted chains remain in a holding pattern under the Cosmos Labs halt advisory, with no confirmed vulnerability, no aggregate loss number, and no restart timeline made public.
Until Cosmos Labs publishes its promised post-mortem, the actual scope of this EVM chains halt event stays unverified, and any chain still running the affected module carries real exposure.
Users and validators tracking this story should rely only on official channels from Labs, KiiChain, TAC, and MANTRA rather than second-hand claims, since details here are still developing and subject to change.
Market analysts note that the pattern across MANTRA, TAC, and KiiChain points to a systemic weakness rather than three isolated events, given all three ran the same shared module.
Until Cosmos Labs names the vulnerable component and confirms which chains remain exposed, other teams running EVM are likely to keep networks halted as a precaution.
The scale of this story across global Crypto News platforms could shape how quickly other SDK chains adopt independent security reviews of shared modules going forward.
Disclaimer: This article covers an active, unresolved security incident with potential price and fund-safety implications for multiple tokens. Figures reflect official disclosures available at the time of publication and may change once Labs releases its full post-mortem. This is not financial advice.