Cosmos Labs advises EVM chains to pause amid spreading exploit
Security & Exploits ·
Cosmos Labs is telling operators of Cosmos EVM-based chains to consider halting validator activity as a security incident tied to the Cosmos EVM module continues to unfold.
The organization's security and engineering staff have reached out directly to affected networks, recommending a temporary shutdown while the root cause is investigated, according to wublockchain.xyz. No technical details about the underlying flaw have been made public, and Cosmos Labs has not named which chains or how much value has been impacted, saying only that a full post-mortem will follow once the situation is contained. A separate advisory from Cosmos Labs reiterated the recommendation for EVM-based chains to pause operations following the disclosure.
This is not the first time the same underlying module has caused trouble. MANTRA previously froze its mainnet for close to 30 hours after running into a related problem. KiiChain reported a more severe outcome: an attacker repeated the same exploit against a Cosmos EVM weakness 18 separate times, extracting roughly 148.3 million KII tokens in the process.
The recurrence across multiple chains built on the same EVM component suggests a shared code-level vulnerability rather than an isolated misconfiguration on any single network, though Cosmos Labs has stopped short of confirming that publicly. The decision to advise a network-wide halt, rather than a targeted patch, points to uncertainty over how many chains remain exposed while the flaw is still being assessed.
What remains unresolved is the scope of the incident: which chains beyond MANTRA and KiiChain may have been contacted or affected, the technical nature of the vulnerability itself, and whether any funds beyond the 148.3 million KII taken from KiiChain have been moved elsewhere. The promised post-mortem from Cosmos Labs, along with any further validator actions across affected networks, will be the next markers to watch.