Cosmos EVM Security Incident Sparks Halt Warnings Across Affected Networks
Cosmos Labs has issued an urgent warning to affected networks in contact with its team to halt operations due to a security incident involving the EVM module. The issue stems from flaws within the Cosmos EVM infrastructure, which have been exploited by attackers.
According to KiiChain, one of the affected chains, delayed warnings allowed exposure to continue as attackers drained funds before the network was halted. The chain detected the activity internally and stopped further theft, but not before an attacker drained 148,326,583.15 KII from wallets on August 22.
KiiChain said the root cause of the vulnerability had been identified, reproduced, and fixed. The issue lies in the shared Cosmos EVM module, rather than KiiChain-specific code, and is attributed to three upstream defects that combined to enable the attack.
MANTRA and TAC have also fallen victim to similar attacks, with MANTRA halting its network for about 30 hours as a precaution. The security incident has raised concerns over the handling of the vulnerability, with KiiChain stating that an emergency halt could have contained the risk much faster than a software upgrade.