A large-scale incident in the Cosmos ecosystem: three blockchain projects using the Cosmos EVM module were forced to halt operations due to the active exploitation of a critical vulnerability. The attack affected the KiiChain, TAC, and MANTRA networks, indicating a systemic issue in the shared code rather than in individual implementations.
The MANTRA team was the first to raise the alarm, stopping the main chain as a precautionary measure. Initially, a "problem in one of the dependencies" was reported, but developers later confirmed that the vulnerability lies precisely in the Cosmos EVM module, which allows Cosmos SDK-based networks to run Ethereum-style smart contracts. The incident affected only two wallets managed by the MANTRA team, while user funds remained untouched. After updating to version 8.4.0, the network resumed normal operation.
Systemic nature of the threat
However, the story did not end there. On August 22, an attacker used the same vulnerability to target KiiChain, applying the exploit 18 times in a row. Within minutes, over 148.32 million KII tokens were drained, after which validators decided to halt the chain at block 9,355,723. The KiiChain team emphasized that the problem lies in the shared Cosmos EVM code (cosmos/evm), which the project used without modifications.
"The vulnerability is in the Cosmos code, not KiiChain. It exists in the shared Cosmos EVM module (cosmos/evm), which the project uses without modifications," the developers stated.
On the same day, the TAC network was also halted at block 24,671,475 after an attacker drained one of the accounts. The TAC team confirmed that the issue is systemic and affects the shared module, not their own code. Cosmos Labs, in turn, redirected all questions to its security specialist and promised to publish a detailed report after the situation is resolved.
My analysis: a lesson for the entire ecosystem
This incident is a vivid example of how a single error in a shared module can paralyze several independent networks at once. For Cosmos, which positions itself as an ecosystem of sovereign blockchains, this is a serious blow to trust. Projects using shared code need to implement stricter audit and monitoring processes, as well as develop emergency response plans. Otherwise, such systemic vulnerabilities will become not an exception, but a sad pattern.