KiiChain Halts Network After EVM Exploit Moves Funds Through Hyperlane to BNB Smart Chain
Key Takeaways
- •An attacker exploited a vulnerability in KiiChain's EVM module to move funds through the Hyperlane interoperability protocol onto BNB Smart Chain, prompting a full chain halt, while Hyperlane itself was not identified as the vulnerable component.
- •KiiChain has confirmed the cross-chain fund movement but has not yet published a verified loss amount, the attacker's address set, or the number of affected accounts.
- •KiiChain shipped a v7.3.0 upgrade in July incorporating a Cosmos Labs-coordinated Cosmos EVM hotfix, and a separate Hacken audit finalized that month recorded 36 findings, including one rated high severity.
- •The breach occurred shortly after the KII token began public trading in mid-August.
- •KiiChain is the latest network to halt block production during a concentrated run of chain-level security incidents, following MANTRA Chain, BounceBit, and Maya Protocol.

KiiChain has halted its blockchain after a vulnerability in its EVM module allowed an attacker to move funds out of the network through the Hyperlane interoperability protocol and onto BNB Smart Chain (BSC).
The team disclosed the halt on X, saying it is tracing the assets with security and infrastructure partners while the network remains stopped. The cross-chain movement has been confirmed, but KiiChain has not yet published a verified loss amount, the attacker's address set, or the number of affected accounts.
EVM Vulnerability Opened Route to BNB Smart Chain
KiiChain operates an EVM-compatible Layer 1 built with the Cosmos SDK. Its EVM module is based on Cosmos EVM, allowing Ethereum-style transactions and smart contracts to run alongside the network's Cosmos infrastructure.
According to the initial disclosure, the vulnerability sits inside that EVM layer. Hyperlane served as the cross-chain route used to move the funds to BSC and has not been identified as the vulnerable component. KiiChain uses Hyperlane as part of its interoperability stack, connecting the network with external blockchains for asset transfers.
The chain halt blocks further transactions while investigators trace the BSC-side fund movements and determine the full scope of the attack. That kind of pause can help limit additional damage, but it also means users and validators remain dependent on later forensic updates before normal activity can resume. The breach comes shortly after the KII token began public trading in mid-August. The token is designed to support transaction fees, network security, and liquidity incentives across KiiChain's onchain foreign-exchange infrastructure.
KiiChain Had Already Patched Cosmos EVM Software in July
KiiChain's EVM stack had undergone security work shortly before the attack. A v7.3.0 upgrade shipped in July using a Cosmos Labs-coordinated Cosmos EVM hotfix that was initially distributed through a private patched dependency ahead of a July 27 public security disclosure. The coordinated upgrade was state-machine breaking and required validators to move to the patched EVM dependency at the same block height.
Sunday's incident disclosure identifies the EVM module as the source of the new vulnerability but does not yet identify the affected function or the transaction sequence involved. That leaves the next technical milestone focused on reproducing the path on-chain and matching it against the earlier patch history.
A separate Hacken audit finalized in July reviewed KiiChain's Layer 1 codebase, including its EVM-related architecture. The assessment recorded 36 findings across the reviewed scope, with 25 resolved, four mitigated, and seven accepted. One finding was rated high severity and six were rated medium.
The current attack will require a transaction-level post-mortem to determine which EVM path was abused and whether the exploited code was part of the previously reviewed or subsequently upgraded software.
KiiChain Halt Follows MANTRA, BounceBit and Maya Exploits
KiiChain is the latest network to stop block production during a concentrated run of chain-level security failures.
A separate MANTRA Chain halt began on August 21 after an attacker exploited an upstream software dependency, forcing validators and MANTRA-managed infrastructure offline while developers prepared a patch. MANTRA's response also included disabling cross-chain infrastructure and tracing fund movements.
BounceBit then chose to permanently retire its Layer 1 following a $3 million BB exploit that allowed 286.5 million BB to move through 14 unauthorized transactions. Its recovery plan will reissue BB directly on BNB Chain from a pre-exploit snapshot.
Earlier in the week, a multi-bug Maya Protocol exploit forced another network-wide pause after roughly $1.7 million in assets was extracted.
KiiChain remains halted while its team and security partners trace the funds moved to BSC. The network's next update is expected after the affected transactions and the loss scope have been verified.