Cosmos Labs Halts Operations Amid Ongoing Security Incident
Cosmos Labs is urging affected networks to halt operations due to an ongoing security incident involving the EVM module. The attacks on KiiChain and TAC have raised security fears, with Cosmos Labs yet to establish whether the incidents stemmed from a common flaw or which networks were specifically instructed to suspend operations.
KiiChain reported that an attacker drained 148,326,583.15 KII from wallets on August 22, repeating the same technique 18 times against different targets. The chain detected the activity internally and halted at block 9,355,723, stopping further theft and freezing funds that remained on the network.
KiiChain attributed the vulnerability to a shared Cosmos EVM module, rather than KiiChain-specific code. Three upstream defects combined to enable the attack, including an underflow in the staking precompile when it writes a post-delegation balance back to the EVM, along with two other undisclosed bugs.