Cosmos EVM chains hit by attacks after public patch release sparks warning failures
A string of attacks has hit blockchains using the Cosmos EVM module, including MANTRA, TAC, KiiChain, and Nesa, with treasury-held protocol reserve tokens stolen and quickly sold on the market. The incidents were later linked by market participants to version v0.7.2 upgrade code published by Cosmos Labs on GitHub on Aug. 19. The release note itself said the version contained an important security fix and urged chains to upgrade through a coordinated process as soon as possible. The controversy centers on how the patch was handled. Critics said Cosmos Labs made the security fix public without privately warning downstream teams or issuing any mandatory upgrade notice to projects relying on the module. Developer @justde said the failure was not the existence of a vulnerability itself, but what happened after it became known: who got warned, who got patched, and whether customers or attackers moved first. KiiChain, one of the affected projects, said the incident could have been avoided and disclosed that the exploit required three upstream flaws in Cosmos EVM to be present at the same time. Nesa said on the night of Aug. 24 that it had detected malicious activity exploiting the Cosmos EVM vulnerability on its L1 and halted the chain while applying fixes and remediation measures. According to the report, its token had already dropped more than 94%, from $0.22 to $0.011. RootData data cited in the article also showed ATOM with an $800 million market capitalization, ranking 68th among tokens, down more than 95% from its peak.








