Cosmos EVM Security Crisis: Labs Urges Chains to Halt Operations Amid Wave of Attacks
Cosmos Labs has warned affected networks to halt operations due to an ongoing security incident involving the Ethereum Virtual Machine (EVM) module. The company's statement comes after KiiChain and TAC reported attacks on their systems, with both chains attributing the issues to flaws within the Cosmos EVM infrastructure.
KiiChain stated that an attacker had drained 148,326,583.15 KII from wallets on August 22, repeating the same technique 18 times against different targets. The chain detected the activity internally and halted at block 9,355,723, stopping further theft and freezing funds remaining on the network.
KiiChain identified three upstream defects that combined to enable the attack: an underflow in the staking precompile when writing a post-delegation balance back to the EVM, along with two other undisclosed bugs. The company linked the issue to the compromises of MANTRA and TAC during the same week.
The handling of the vulnerability has come under scrutiny, with KiiChain criticizing Cosmos Labs for not providing advance notice or clearly flagging the release as a critical security update. A security fix for one of the flaws was made public on August 19, but affected networks were not informed until two days later, when the fix was included with unrelated issues already being handled privately.