Cosmos Labs Advises ATOM Ecosystem Chain Halts After 148.33M KII Exploit

Cosmos Labs advised Cosmos EVM chains to halt validators after KiiChain lost 148.33M KII; TAC and MANTRA also paused networks.

(11:16 PM UTC)
4 min read
AI SummaryAI
  • MANTRA paused its layer-1 network for about 30 hours, with no user funds lost.
  • KiiChain lost 148,326,583.15 KII across 18 identical attacks on Aug. 22.
  • KiiChain halted at block height 9,355,723 after detecting abnormal activity.
  • 80,728,575.06 KII (54.4%) remained in attacker-linked addresses on KiiChain.
v3xn8bwc

The Cosmos (ATOM) ecosystem has been put on alert after Cosmos Labs advised networks using the shared Cosmos EVM module to halt their chains, describing an ongoing security incident that has already led to asset losses on KiiChain and TAC. Cosmos EVM is not a single blockchain but common software that lets appchains built on Cosmos SDK run Ethereum-compatible smart contracts, meaning a flaw in the shared layer can expose several independently operated networks at once. In an official post on X, Cosmos Labs said its security and engineering teams were actively responding and that chains in contact with it should request validators to stop block production. Validators carry out the actual halt, since Cosmos Labs does not switch off chains directly. It said a detailed incident report would be published after the situation was resolved, but it did not identify which networks had been advised or the total value at risk. The advisory followed a week of incidents across the Cosmos EVM ecosystem: KiiChain reported the theft of 148,326,583.15 KII on Aug. 22, TAC reported the movement of 2,985,650,000 TAC between accounts, and MANTRA paused its layer-1 network for about 30 hours. KiiChain said it detected abnormal activity internally and halted its chain at block height 9,355,723, freezing funds that remained on the network and preventing further draining. TAC said no new TAC tokens were minted and total supply was unchanged. MANTRA said only two wallet addresses were affected, with no user funds taken, and it resumed operations after applying a fix. The three projects each pointed to the shared Cosmos EVM infrastructure rather than their own code. Cosmos Labs has not officially confirmed whether all three incidents stem from the same vulnerability, leaving the scope of exposure unresolved.

The most detailed accounting came from KiiChain, whose incident report published Aug. 24 described 18 identical attacks against different wallets and a total loss of 148,326,583.15 KII. The attacker exploited what KiiChain called at least three combined flaws in the shared Cosmos EVM code. One confirmed flaw was an underflow error in the staking precompile, a mechanism that writes post-delegation balances back to the EVM; KiiChain said the attack also required a vesting account and a contract deployed at a precomputed address. The chain stressed that the stolen KII did not increase total supply, because the attacker moved existing balances rather than minting new tokens. Of the total taken, 80,728,575.06 KII, or 54.4%, remained in attacker-linked addresses on KiiChain, and the chain plans to move those funds to a recovery wallet during its restart upgrade. The remaining 67,597,997.87 KII was moved through the cross-chain protocol Hyperlane to BNB Smart Chain, where 64,597,997.87 KII was sold for roughly 1,610,000 BUSD through an automated market maker and 3,000,000 KII was sent to a KuCoin deposit address. KiiChain said it asked KuCoin to verify the account and freeze those tokens, but had not received confirmation at the time of writing. The report also criticized Cosmos Labs' vulnerability disclosure process. A patch for one of the flaws was pushed to a public repository on Aug. 19 as Cosmos EVM v0.6.2 and v0.7.2, with an urgent coordinated upgrade recommended, but KiiChain said affected downstream chains were not notified in advance. KiiChain said it did not receive related communication from Cosmos Labs until Aug. 21, and that the potential for permanent asset loss and the need for a chain halt were not clearly communicated. It argued that a coordinated stop of block production would have contained the risk faster than a software patch, which requires validators to review, build and deploy changes. KiiChain added that only the underflow flaw had been fixed upstream by Cosmos Labs at the time of its report, while other issues remained unpatched in the shared module.

The pattern points to a shared-infrastructure risk: one upstream bug can become a multi-chain event. KiiChain's post-mortem identifies the staking precompile underflow in the Cosmos EVM module as the root cause, and on-chain evidence shows most stolen KII never left KiiChain, reinforcing that coordinated halts work. Unresolved is whether Cosmos Labs' disclosure process left other Cosmos SDK appchains exposed before the patch. For ATOM holders, the episode shows validator coordination and clear severity warnings matter as much as the code fix. Cosmos Labs' full incident report is pending, and whether it confirms a shared root cause will shape the ecosystem's security posture.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.