A large-scale incident exposed a critical security flaw in the Cosmos EVM module, forcing three major blockchain projects to urgently suspend their operations. This is not a series of isolated attacks, but a systemic issue affecting a fundamental layer of the Cosmos SDK infrastructure.
MANTRA was the first to raise the alarm, halting its network to prevent potential damage. The team quickly confirmed that the vulnerability lies precisely in the Cosmos EVM module, which ensures compatibility with Ethereum smart contracts. Fortunately, in MANTRA's case, only two wallets controlled by the team itself were affected, and user funds remained untouched. After updating to version 8.4.0, the network resumed normal operations.
However, for KiiChain, the consequences were far more severe. An attacker exploited the same vulnerability 18 times in a row, managing to withdraw over 148.32 million KII tokens before validators decided to halt the chain at block 9,355,723. Developers emphasize that the issue is not in their code, but in the common cosmos/evm module, which is used without modifications. The network has not yet been restored — the launch will occur through a coordinated binary code update that validators will apply simultaneously.
On the same day, TAC was also forced to stop its network at block 24,671,475 after a hacker drained one of the accounts. The TAC team, like their colleagues at KiiChain, directly points to the common module as the source of the problem, shifting responsibility away from their own code.
Cosmos Labs, in turn, redirected all questions to its security specialist and promised to publish a detailed report after the situation is resolved. The causes of the attack have not yet been disclosed.
My analysis of the situation
This incident is a striking example of how a single error in the base layer can paralyze several independent ecosystems at once. For Cosmos, this is a serious blow to its reputation, as the EVM module was positioned as a reliable bridge between the Cosmos and Ethereum worlds. The good news is that the teams acted quickly, and the damage to users appears to be minimal. However, without a public report and a detailed breakdown of the root causes, trust in the ecosystem will remain in question. Investors should closely monitor developments and assess how projects will strengthen security after this lesson.