Particle.news

Cosmos EVM Module Under Active Attack as Chains Are Urged to Halt

A shared bug in the ICS20 precompile may allow attackers to move tokens across independent Cosmos SDK chains, freezing services and risking asset loss.

Overview

  • Cosmos Labs disclosed an active security incident on Aug. 24 and told teams using the Cosmos EVM module to coordinate validator halts while its security and engineering teams investigate.
  • The incident has produced confirmed drains: KiiChain said an attacker took 148,326,583.15 KII in 18 repeated exploits on Aug. 22, and TAC reported one account drained before validators stopped the chain that same day.
  • MANTRA halted on Aug. 20 after abnormal activity, deployed emergency patches, and resumed block production about 30 hours later while saying user balances were unchanged.
  • Investigators link the attacks to the ICS20 precompile, a cross-chain token-transfer component tied to ASA-2026-002 disclosed in March, raising questions about whether the March patch fully fixed incorrect state handling during nested EVM execution.
  • Cosmos Labs has not published a full list of affected chains, a technical root cause, or aggregate losses and said it will release a post-mortem that should identify affected versions, the exploitation timeline, and safe restart steps.