KiiChain Confirms 148.3M KII Drain in Cosmos EVM Exploit
KiiChain lost 148.3M KII in a Cosmos EVM module exploit; MANTRA resumed after fix 8.4.0. MEXC Japan warns of fake SMS phishing.
AI SummaryAI
- KiiChain lost 148,326,583.15 KII in 18 exploit transactions.
- Validators halted KiiChain at block 9,355,723 after the drain.
- MANTRA resumed block production after the fix in Cosmos EVM version 8.4.0.
- TAC halted at block 24,671,475 after one account was drained.
KiiChain Loses 148.3M KII in Cosmos EVM Exploit
KiiChain, a Cosmos-based network, lost 148,326,583.15 KII after an attacker exploited the shared Cosmos EVM module, the component that allows Cosmos SDK chains to run Ethereum-style smart contracts. KiiChain said that on Aug. 22 the attacker repeated the same technique 18 times before validators halted the chain at block 9,355,723. Its official disclosure on X states that the vulnerability sits in the Cosmos EVM module, which KiiChain runs unmodified, rather than in KiiChain-specific code. The network has remained halted since, and it plans to restart through a coordinated binary upgrade at a predetermined block height, with all validators applying the update simultaneously and no on-chain governance proposal required. The disclosure came as part of a broader cluster: Cosmos Labs has confirmed an ongoing security incident affecting users of the Cosmos EVM module and advised affected chains to ask validators to pause block production. TAC also stopped its chain the same day at block 24,671,475 after one account was drained, and its statement likewise pointed to the shared module rather than TAC-specific code. MANTRA paused earlier as a precaution after two MANTRA-managed wallets were affected, with the team initially describing the issue as an upstream dependency. MANTRA later said the flaw had been fixed in version 8.4.0 and that normal block production has resumed, with user balances never impacted. All three networks named the Cosmos EVM module in their disclosures, and Cosmos Labs has not yet described the precise cause; it has pointed teams with questions to its security contact and said it will publish an incident report once the situation is resolved. The episode underscores how a defect in an altcoin ecosystem's shared infrastructure can ripple across multiple networks at once.
MEXC Japan Flags Fake Authentication SMS
On Aug. 23, MEXC Japan, the Japanese-facing arm of the crypto exchange MEXC, warned that fraudulent SMS messages impersonating its authentication-code alerts are circulating. In an official notice on X, the exchange said multiple users had reported receiving texts beginning with “[MEXC]認証コード” since the evening of Aug. 23. The messages contain a link to “mexc.sc,” a domain that is not an official MEXC address, and are designed to steer recipients to a phishing page that collects IDs and passwords. MEXC Japan noted that the sender name displays as “MEXC,” matching legitimate messages, and that the fake texts can appear on a user's device alongside real authentication codes, making them hard to distinguish. The exchange said it never includes links in its official SMS and advised users to treat any link-bearing message as fake. It also pointed users to an official guide that walks through red flags in SMS phishing. MEXC Japan urged customers to access their accounts through the official app rather than following SMS links, and said staff never ask for authentication codes by phone or direct message. As of the warning, no unauthorized logins or asset movements had been confirmed; the exchange said accounts were not at risk unless credentials had already been entered on the fake page. MEXC Japan is also investigating whether phone numbers were obtained from its own systems, including the possibility of a leak from MEXC itself, and said it will publish further findings on its X account. Users who entered credentials on the fraudulent site were told to change their passwords immediately, update any reused passwords elsewhere, and contact MEXC's 24-hour Japanese-language support. The incident highlights the trust gap in SMS-based security for altcoin holders and shows how a single unsolicited message can mimic anything from a legitimate airdrop notification to a security alert.
Shared-Trust Lesson for Cosmos and Exchanges
The two events are different in mechanism but converge on the same theme: users and networks are only as secure as the trusted infrastructure beneath them. For KiiChain, the immediate task is restarting safely; for MEXC, it is closing the window for credential theft. On-chain records confirm the 148.3 million KII drain, and official incident statements from KiiChain, MANTRA and TAC all attribute the failure to the shared Cosmos-EVM module rather than chain-specific code, with the fix delivered in version 8.4.0. Our reading of the episode is that Cosmos-based chains will face pressure to audit shared dependencies more aggressively, while the MEXC warning reinforces that exchanges must treat out-of-band communications as a real attack surface for the altcoin economy.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


