Cosmos EVM chains hit by attacks after public patch release sparks warning failures

Cosmos EVM chains hit by attacks after public patch release sparks warning failures

N
News Editor
2026-08-25 02:41:56
A string of attacks has hit blockchains using the Cosmos EVM module, including MANTRA, TAC, KiiChain, and Nesa, with treasury-held protocol reserve tokens stolen and quickly sold on the market. The incidents were later linked by market participants to version v0.7.2 upgrade code published by Cosmos Labs on GitHub on Aug. 19. The release note itself said the version contained an important security fix and urged chains to upgrade through a coordinated process as soon as possible. The controversy centers on how the patch was handled. Critics said Cosmos Labs made the security fix public without privately warning downstream teams or issuing any mandatory upgrade notice to projects relying on the module. Developer @justde said the failure was not the existence of a vulnerability itself, but what happened after it became known: who got warned, who got patched, and whether customers or attackers moved first. KiiChain, one of the affected projects, said the incident could have been avoided and disclosed that the exploit required three upstream flaws in Cosmos EVM to be present at the same time. Nesa said on the night of Aug. 24 that it had detected malicious activity exploiting the Cosmos EVM vulnerability on its L1 and halted the chain while applying fixes and remediation measures. According to the report, its token had already dropped more than 94%, from $0.22 to $0.011. RootData data cited in the article also showed ATOM with an $800 million market capitalization, ranking 68th among tokens, down more than 95% from its peak.

A wave of security incidents has swept through the Cosmos ecosystem over the past few days, hitting blockchains that use the Cosmos EVM module, including MANTRA, TAC, KiiChain, and Nesa. In each case, protocol reserve tokens held in treasury wallets were stolen and then rapidly sold, sending KII, TAC, and NES down by more than 90% within hours, according to ChainCatcher.

GitHub release on Aug. 19 became the common thread

At first, the market did not connect the incidents, even though all of the affected networks were Cosmos-based chains. Attention shifted only later, when participants began tracing the attacks back to version v0.7.2 upgrade code published by Cosmos Labs on GitHub on Aug. 19.

On that GitHub page, Cosmos Labs wrote: 「This version contains important security fixes. We recommend that all chains upgrade to this patch version as soon as possible through a coordinated upgrade process. This release is disruptive.」 The wording itself signaled urgency and suggested the vulnerability was serious.

The handling of that patch has since become the center of the dispute. Critics said Cosmos Labs made the security fix fully public without privately warning project teams that rely on the module or issuing any mandatory upgrade notice.

Criticism focused on warning and coordination, not just the bug itself

Developer @justde said: 「If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will happen. The standard for enterprise infrastructure is everything that happens after the bug exists: who was exposed, who got warned, who got the patch, and whether customers or attackers moved first. We need a full postmortem from Cosmos Labs. But there is no way to dress this up: the coordination failed very badly.」

KiiChain, which was also attacked, directly accused Cosmos Labs of acting irresponsibly and said the incident 「could have been avoided.」

According to KiiChain, when Cosmos Labs put out its notice on Friday, it bundled the fix together with a batch of unrelated issues that had previously been handled privately. KiiChain said the issue was not treated as an extreme emergency in the way a severe vulnerability with a risk of permanent fund loss should have been, and that Cosmos Labs did not advise all chains to pause.

KiiChain disclosed exploit conditions tied to three upstream flaws

KiiChain also described how the exploit worked. It said the attack required three upstream defects in the Cosmos EVM module to be present at the same time. One of them involved an underflow during a staking precompile, when the delegated balance was written back into the EVM. The other two vulnerabilities have not yet been disclosed.

KiiChain added that its own chain-specific code did not play a role in the attack. It also said all Cosmos EVM chains that have vesting accounts enabled faced the same risk.

Nesa halted its chain on Aug. 24 after detecting active exploitation

The attacks were still ongoing as of the night of Aug. 24. Nesa then issued a statement and moved to pause its blockchain. The team said: 「We have identified malicious activity on the L1 exploiting the Cosmos EVM vulnerability and are taking measures to contain the impact. We have acted quickly and will restore service once software fixes and additional remediation steps are in place to ensure safe operations.」

By that point, the Nesa token had already fallen more than 94%, dropping from $0.22 to $0.011, the report said.

The article also noted that after multiple Cosmos EVM security incidents had already occurred and the issue had been exposed for at least two days, Nesa still had not taken proactive steps to reduce risk. It cited that as a sign of weak risk awareness and accountability inside the project’s technical team.

MANTRA pointed to Cosmos EVM on Aug. 21, while Cosmos Labs responded later

As early as Aug. 21, MANTRA had publicly said it had identified the root cause of its incident and that the issue was limited to the Cosmos EVM module on MANTRA Chain.

As debate spread, Cosmos Labs eventually issued a public response, saying: 「An ongoing security incident is affecting users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been actively responding to this event. We have advised Cosmos EVM chains that contacted us to ask validators to halt their chains.」

That response did little to calm criticism on social media. @justde also wrote: 「They maintain a shared EVM module that dozens of chains rely on, but when a critical precompile bug appeared, they did not proactively push a patch through the primary channels, did not provide a clear PoC, and did not provide coordinated deployment guidance. These chains are downstream of your code. Your job is to ship a security patch quickly plus a ready-to-deploy PoC so the ecosystem can upgrade cleanly. Instead, what we got was silent breakage from upstream, and every team was left struggling on its own.」

RootData figures show ATOM at $800 million market cap

RootData data cited in the article showed that Cosmos token ATOM still had a market capitalization of $800 million, ranking 68th among all tokens, though it was down more than 95% from its peak.

The article said the ecosystem has also faced setbacks over the past several years. In the past six months alone, Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation announced they would stop operating, while Secret Network and Noble said they would leave the Cosmos ecosystem and either build their own Layer1 or move into Ethereum’s ecosystem.

The chain of thefts has again exposed concerns around base-layer code auditing, cross-chain coordination, and emergency response across Cosmos, according to the report. The article’s sharpest criticism was aimed at the decision to make a high-risk patch public without adequately notifying downstream teams at the same time.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
130

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.