Cosmos Labs Orders Cosmos EVM Chains to Halt as Security Incident Spreads Across Shared Stack
Key Takeaways
- •Cosmos Labs asked validators running Cosmos EVM-based chains to halt operations after a fresh security incident.
- •MANTRA Chain paused block production after detecting suspicious activity and later said the issue had been contained.
- •KiiChain reported that an attacker exploited a flaw to manipulate balances and drain about 148 million KII.
- •Cosmos EVM’s shared software architecture means a vulnerability can affect multiple independent networks at the same time.
- •Cosmos Labs said it will publish a detailed report after the incident is contained.

Cosmos Labs has called on validators running chains built with its Cosmos EVM module to suspend network operations after a new security incident raised concerns across the ecosystem. The advisory comes as several Cosmos-based networks experienced disruptions and reported exploits tied to the shared software stack.
The warning follows a turbulent week for Cosmos EVM chains. MANTRA Chain halted its network, pausing block production, after detecting suspicious activity and later said the incident had been contained. According to the team, two wallet addresses were affected, but user funds were not exploited. MANTRA subsequently prepared a patched software release and coordinated with validators before resuming operations.
KiiChain and TAC also reported security incidents involving vulnerabilities in components connected to the Cosmos EVM environment. KiiChain said an attacker exploited a flaw that enabled unauthorized balance manipulation, draining approximately 148 million KII, the network's native token, across multiple transactions before the chain was frozen.
Shared software raises ecosystem-wide risks
Cosmos EVM provides Ethereum Virtual Machine compatibility to Cosmos-based blockchains, allowing developers to deploy Ethereum-style smart contracts while building on the Cosmos stack. The trade-off is that a vulnerability in a shared component can potentially affect multiple independent networks simultaneously.
The latest warning follows an earlier Cosmos EVM vulnerability disclosed this year. That flaw involved incorrect state handling during nested EVM execution and led to losses on Saga EVM. Cosmos Labs later released a permanent fix and coordinated upgrades with the affected chains.
Shared-component risk has surfaced elsewhere in the Cosmos ecosystem before. In October 2022, a critical vulnerability in the IBC inter-blockchain communication protocol prompted coordinated emergency upgrades across multiple Cosmos-based networks, an earlier case where the response depended on validators patching in unison to contain ecosystem-wide exposure.
The current incident remains under investigation, and Cosmos Labs has said it will publish a detailed report after the situation is contained. Until then, validators face uncertainty over which networks remain exposed and whether additional chains could be affected.
The episode highlights the security challenge facing blockchain ecosystems that rely on common infrastructure. A single vulnerability can turn an isolated exploit into a broader industry incident, making rapid disclosure, coordinated upgrades and validator cooperation critical to limiting losses.