Overview
- Cosmos Labs disclosed an active security incident on Aug. 24 and told teams using the Cosmos EVM module to coordinate validator halts while its security and engineering teams investigate.
- The incident has produced confirmed drains: KiiChain said an attacker took 148,326,583.15 KII in 18 repeated exploits on Aug. 22, and TAC reported one account drained before validators stopped the chain that same day.
- MANTRA halted on Aug. 20 after abnormal activity, deployed emergency patches, and resumed block production about 30 hours later while saying user balances were unchanged.
- Investigators link the attacks to the ICS20 precompile, a cross-chain token-transfer component tied to ASA-2026-002 disclosed in March, raising questions about whether the March patch fully fixed incorrect state handling during nested EVM execution.
- Cosmos Labs has not published a full list of affected chains, a technical root cause, or aggregate losses and said it will release a post-mortem that should identify affected versions, the exploitation timeline, and safe restart steps.