Cosmos EVM Module Security Incident Results in 148 Million KII Token Loss
A security incident has impacted users of the Cosmos EVM module, according to an announcement by Cosmos Labs on August 25.
The issue affects multiple chains that utilize the module, including KiiChain, TAC, and Mantra. An attacker exploited a vulnerability in the shared Cosmos EVM code, resulting in a loss of approximately 148 million KII tokens from KiiChain.
KiiChain discovered the abnormal asset outflow internally and halted its chain at block height 9,355,723 on August 22 at 22:50:58 UTC. The attacker utilized a vesting account to exploit the vulnerability, which allowed them to move assets between chains.
Cosmos Labs advised chains using the EVM module to halt their operations to prevent further asset movement and potential losses. KiiChain has implemented measures to mitigate future attacks, including introducing a 24-hour limit on KII token movements via Hyperlane.