Cosmos Labs, the organization responsible for maintaining key components of the Cosmos blockchain ecosystem, publicly addressed a developing security concern tied to its Cosmos EVM module. This open-source component enables Cosmos SDK-based networks to support Ethereum Virtual Machine-compatible smart contracts, allowing developers to deploy familiar Ethereum-style applications on independent Cosmos chains.
Because the module is shared across multiple projects, a flaw in it can create exposure for several networks at once rather than remaining isolated to a single chain.
On August 24, 2026, Cosmos Labs posted a statement noting that an active security incident had affected users of the Cosmos EVM module.
The organization’s security and engineering teams were actively working to contain the issue.
As a precautionary step, Cosmos Labs recommended that the Cosmos EVM chains with which it maintains contact instruct their validators to pause block production.
The firm expressed appreciation for the quick actions taken by teams relying on the module and committed to releasing a detailed incident report after the matter is fully resolved.
Affected projects seeking guidance were directed to reach out via the designated security contact, security@cosmoslabs.io. At the time of the announcement, Cosmos Labs withheld specifics about the precise vulnerability, the full list of impacted networks, or any quantified losses.
The advisory followed a series of separate disclosures from individual chains that also rely on the shared Cosmos EVM infrastructure.
MANTRA, focused on real-world asset applications, detected unauthorized activity and temporarily stopped operations around August 20–21.
The network later indicated that the root cause lay in the Cosmos EVM module, applied a software update, and resumed block production after roughly 30 hours.
Officials stated that only certain internal wallets under MANTRA’s control were involved and that ordinary user balances remained unaffected.KiiChain reported a more extensive impact.
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…
— Cosmos Labs (@cosmoslabs_io) August 24, 2026
On August 22, an attacker repeatedly used the same technique across 18 instances, resulting in the removal of approximately 148.3 million KII tokens from various wallets before validators halted the chain.
The project linked the activity to issues involving vesting accounts, staking operations, and balance handling within the Cosmos EVM layer.
Some of the moved assets were later bridged elsewhere.
TAC similarly suspended operations on August 22 after an attacker emptied a single account by exploiting a weakness in a Cosmos EVM precompile.
Validators stopped the network at a specific block height, and the team emphasized that the problem originated in the shared module rather than in TAC’s own code.
These overlapping events illustrate the risks inherent in widely adopted shared software layers.
When multiple independent blockchains integrate the same upstream components, a single defect can propagate across the ecosystem.
Earlier in 2026, related concerns around precompile handling and state management had prompted patches and mitigations in the Cosmos EVM stack, underscoring the ongoing need for rigorous auditing, coordinated disclosure practices, and rapid response mechanisms.
As of the latest available information, Cosmos Labs continues its investigation and has not yet published the promised full post-mortem.
Chains that have not already halted are evaluating their configurations, while those that paused are awaiting guidance on safe restart procedures and any required upgrades.
The incident now serves as yet another stark reminder of both the benefits and the responsibilities that come with modular blockchain design: shared infrastructure accelerates development and interoperability, yet it also demands heightened vigilance and transparent communication among maintainers and operators to protect users across the broader network of networks.