Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks
Cosmos Labs disclosed a critical vulnerability in its Cosmos EVM module affecting multiple chains. Attackers drained at least $9.7 million from KiiChain and approximately $7.5 million from TAC between August 20-22. The incident follows a disclosure failure: Labs published a security fix publicly on August 19 without notifying affected chains privately, creating a two-day exploit window.
Who this affects
Quoted from the advisory linked below. The desk does not restate it.
- Affected
- any public blockchain running a version of its Cosmos EVM module below v0.6.2 or v0.7.2
- Fixed in
- v0.6.2 or v0.7.2
- What to do
- immediately halt the blockchain and upgrade it to include the patches in those releases
Cosmos Labs recommended on Tuesday that any public blockchain running a version of its Cosmos EVM module below v0.6.2 or v0.7.2 immediately halt and upgrade to patch a critical vulnerability. The vulnerability had already been exploited: three chains running the module, MANTRA, TAC, and KiiChain, were attacked between August 20 and 22, with attackers draining at least $9.7 million from KiiChain and approximately $7.5 million from TAC, according to The Defiant.
The vulnerability is composed of three upstream defects: an underflow in the staking precompile when it writes a post-delegation balance back to the EVM, plus two bugs that remain undisclosed. The exploit worked by computing the address of a contract before deployment, converting that address into a vesting account, then deploying the contract onto it. The contract inherited vesting status, delegated one wei more than its spendable balance, and underflowed its mirrored EVM balance to approximately 2^256, giving the attacker access to a near-infinite balance.
KiiChain halted the network at block 9,355,723 on August 22 at 22:50:58 UTC after attackers drained 148 million KII in 18 repeated attacks against different targets. About 80.7 million KII, or 54.4 percent, sits in attacker addresses that the halt immobilized and will be moved to recovery wallets at restart. However, 67.6 million KII was bridged to BNB Smart Chain through Hyperlane and sold on decentralized exchanges for roughly 1.61 million BUSD. A final 3 million KII went to a KuCoin deposit address; KiiChain said confirmation is still pending on whether it can be recovered. TAC halted at block 24,671,475 on August 22 at 23:58 UTC after an attacker drained 2.9 billion TAC, representing approximately 62 percent of the token's circulating supply. TAC said on August 24 it would publish a post-mortem and relaunch plan the following day, according to The Defiant; neither had appeared by Tuesday afternoon.
The disclosure timeline exposes how a breakdown in responsible disclosure practices turned a patchable bug into a live exploit window. Cosmos Labs published a fix for one of the three defects in a public repository on August 19 but gave no advance notice to downstream chains, did not flag the release as security-critical, and did not tell affected chains that a public release had happened until Friday, August 21, two days later. The halt recommendation was not made until August 22, after MANTRA, TAC, and KiiChain had all been compromised. MANTRA halted late on August 20 at block 17,449,398 and says block production resumed at 05:30 UTC on August 22 on a patched v8.4.0 binary. Nesa and MANTRA halted in advance of Cosmos Labs' warning, with seemingly no user funds affected.
The v0.6.2 and v0.7.2 release notes both carry generic boilerplate language, stating they contain important security fixes and are state-breaking, with no CVE, no advisory reference, and nothing identifying the entry as a live exploit path. The cosmos/evm advisory page still lists three published advisories, the newest from March. Two of the three defects remain unfixed upstream at Cosmos Labs; only the underflow has been patched publicly. Any Cosmos EVM chain with vesting accounts enabled that has applied the official upstream fix alone remains exposed to the other two defects. Cosmos Labs has commented on the incident twice, both times on social media, and has not responded to KiiChain's account of the disclosure. KiiChain called the loss avoidable in a post-mortem report, openly blaming Cosmos Labs' disclosure process for creating what it termed the window it was robbed in.
Another Cosmos EVM network, Saga EVM, lost approximately $7 million in January, indicating a pattern of vulnerability across chains using the module.
Three chains running Cosmos EVM module were attacked between Aug. 20 and Aug. 22 after Cosmos Labs published a security fix publicly without first notifying downstream chains; KiiChain lost 148 million KII (worth $9.7 million) and TAC lost 2.9 billion TAC (worth $7.5 million).
Watch for Cosmos Labs to publish a formal security advisory or CVE that names the two undisclosed defects and identifies which chains remain exposed after applying only the public patch. The status of fund recovery on KiiChain, TAC, and the KuCoin deposit address will signal whether affected chains can restore user balances through coordination with exchanges or protocol-level remediation. If the other two defects remain unfixed upstream and undisclosed, the premise that a published patch provides security will be invalidated.
And that's the way it is.
Sources
Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.
