Cosmos EVM Module Bug Drains Three Networks
Cosmos Labs recently recommended that any public blockchain running its Cosmos EVM module below v0.6.2 or v0.7.2 should immediately halt and upgrade to include patches in those releases.
This warning comes after a shared bug drained three networks: KiiChain, Mantra, and TAC. The attack targeted chains with vesting accounts enabled, and Cosmos Labs has published no security advisory for the flaw.
KiiChain reported that an attacker stole 148 million tokens worth roughly $9.7 million at the time of the incident. Two of the three underlying defects remain unfixed upstream, according to KiiChain's report.
Cosmos Labs published a fix for one of the three defects on August 19, but did not give advance notice to downstream chains or flag the release as security critical. The company finally recommended halting blockchains on August 22, after Mantra, TAC, and KiiChain had already been compromised.