Cosmos EVM Networks Halt as Hackers Exploit Vulnerabilities
Cosmos Labs has urged networks using its Ethereum Virtual Machine (EVM) module to halt their chains due to vulnerabilities affecting the software. This comes after several Cosmos EVM networks took defensive action and KiiChain suffered the largest confirmed loss, with an exploit moving 148.33 million KII through 18 attack rounds before validators stopped the network.
The attack abused vulnerabilities in shared Cosmos EVM components rather than KiiChain-specific application code, expanding the security issue beyond a single network. About half of the stolen tokens remain recoverable, with around 80.73 million KII frozen at attacker-controlled addresses and another 67.6 million transferred to BNB Smart Chain.
KiiChain remains halted while its patched upgrade is prepared, with the restart plan including recovering the remaining tokens and adding withdrawal limits to cross-chain routes before normal operations resume. Warden Protocol has released a patch, upgrading Cosmos EVM to v0.6.2 and blocking the creation of vesting accounts through the affected path.