NewsCryptoCosmos Labs Urges Cosmos EVM Chains to Halt Networks Amid Active Security Incident

Cosmos Labs Urges Cosmos EVM Chains to Halt Networks Amid Active Security Incident

Author: CryptoBriefing·

Key Takeaways

  • Cosmos Labs said an active security incident is targeting chains built with its Cosmos EVM module.
  • The company urged affected networks to halt block production while its teams investigate the issue.
  • Cosmos Labs said it will release a detailed incident report after the situation is contained and resolved.
  • A January exploit involving SagaEVM caused about $7 million in losses and affected multiple chains running related code.
  • MANTRA Chain and TAC both halted their networks in August following separate Cosmos EVM-related security incidents.
Cosmos Labs Urges Cosmos EVM Chains to Halt Networks Amid Active Security Incident

Cosmos Labs disclosed on August 24 that an active security incident is targeting chains built with its Cosmos EVM module, a plug-and-play layer that gives Cosmos SDK chains compatibility with the Ethereum Virtual Machine and lets them run Ethereum-style smart contracts and tooling. The company has urged affected Cosmos EVM chains to halt their networks, offering blunt guidance to validators: stop your networks.

The company said its security and engineering teams are actively working on the incident, while the scope and nature of the issue remain unclear. A detailed incident report will be released once the situation is contained and resolved, according to the team. Halting block production is one of the few emergency controls available on Cosmos SDK-based networks, where a coordinated validator stop pauses transaction processing while engineers investigate and patch affected code — the containment playbook MANTRA Chain used days earlier.

The disclosure is the latest in a series of security incidents that have affected the Cosmos EVM ecosystem in 2026. The first major incident came in January, when an exploit involving the SagaEVM implementation caused approximately $7 million in losses. Cosmos Labs identified 15 chains running code containing the relevant vulnerability, although six had not enabled the affected feature. One chain was exploited, while the others reportedly mitigated the issue before attackers could act. The January episode also showed how a flaw in widely shared module code can reach many chains at once, since networks that adopt the same plug-and-play component inherit the same code.

The ecosystem saw further disruption in August. MANTRA Chain halted block production for roughly 30 hours following an incident involving its Cosmos EVM module. MANTRA said two wallet addresses it managed were affected and that no user funds were exploited. The chain resumed operations on August 22 after deploying a patch.

TAC also halted its chain on August 22 after reporting an exploited vulnerability affecting its Cosmos-based EVM environment and token supply. With the newest incident still active, the open questions are how many chains act on the halt request, whether further halts follow, and what detail Cosmos Labs' promised incident report will provide once the situation is contained.