Cosmos EVM Vulnerability Should Alarm Multichain Ecosystems
Cosmos EVM’s latest vulnerability exposes the security risks of shared blockchain infrastructure and raises serious questions about multichain coordination.
The Cosmos EVM problem is more than a typical blockchain vulnerability. It shows the consequences of independent networks using the same code but not receiving or executing security updates at the same time. MANTRA, KiiChain, TAC, and Nesa were openly connected to attacks or defensive halts involving the common Cosmos EVM module in late August.
According to KiiChain, 148,326,583 KII were drained, but according to TAC, an attacker only drained one account before the chain was stopped by validators. Then, Cosmos Labs asked Cosmos EVM chains that were in contact with it to stop validators.
One Vulnerability, Multiple Chains at Risk
Validators, apps, treasuries, and users were not required to be shared among affected projects. Their mutual reliance was sufficient. EVM compatibility, Ethereum tooling, and precompiles linking EVM execution with native Cosmos functionality are all provided via Cosmos EVM, a plug-and-play layer that can be incorporated into Cosmos SDK chains. The blast radius is significant because of this convenience.
MANTRA, KiiChain, TAC, and Nesa are the names that have been made public. once suspicious activity, MANTRA stopped, but it eventually started up again once a fix was implemented and no user funds were impacted. Before validators stopped the chain, KiiChain reported that 148.3 million KII were drained. After an account was depleted, TAC stopped at block 24,671,475 and stated clearly that the flaw was in the shared Cosmos EVM module rather than TAC-specific code. Nesa halted its network after reporting malicious activity that took use of a Cosmos EVM vulnerability.
Source: KiiChain Security Incident
Because each chain had unique configurations and assets, the results varied. However, reliance was widespread. The key security lesson is that if the same weak assumption underlies four security teams, attackers do not need to defeat them separately when the infrastructure is reused.
Source: KiiChain Security Incident
Saga EVM's roughly $7 million loss in January came from a separate Cosmos EVM vulnerability involving the ICS20 precompile. It is separate from August, but shows shared EVM infrastructure has already required serious security response this year.
Source: KiiChain Security Incident
The Hidden Risk of Shared Infrastructure
Efficiency is promised by modularity, i.r., construct once, reuse over numerous chains. The other half is required for security, i.e., compromise once, look everyplace.
Users seldom see the dependency graph that is produced by a common module. A chain may inherit a crucial vulnerability from upstream software even if it has its own validators, governance, tokenomics, and application code. Therefore, infrastructure exposure is not eliminated by passing local contract audits.
For this reason, the episode should concern not only Cosmos but all multichain ecosystems. Security becomes a supply-chain issue as more projects use common execution environments, bridges, messaging layers, account systems, or precompiles. The extent to which a component is integrated determines the scope of a vulnerability.
Cosmos EVM is a Go library that can be imported and utilized by various networks. Its architecture is intentionally reusable. Dependency inventories, version tracking, emergency contacts, verified upgrade pathways, and unambiguous incident ownership are all essential components of a reusable security model.
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…
— Cosmos Labs (@cosmoslabs_io) August 24, 2026
Additionally, the current episode demonstrates that version awareness is not the same as security awareness. Cosmos EVM released versions 0.6.2 and 0.7.2 on August 19. Both versions were clearly stated to contain significant security changes, and coordinated upgrades were advised. However, attacks came days later. Finding a defect and safeguarding each downstream deployment before an attacker uses the patch as a roadmap constitute the dangerous gap.
We recommend that if you run a public chain that uses a Cosmos EVM version less than v0.6.2 and v0.7.2, you should immediately halt the blockchain and upgrade it to include the patches in those releases.
— Cosmos Labs (@cosmoslabs_io) August 25, 2026
If you use Cosmos EVM and have not yet provided us with your security…
Is Multichain Security Coordination Good Enough?
The Cosmos episode becomes an institutional test at this point.
A formal vulnerability disclosure policy based on coordinated disclosure and private reporting exists at Cosmos Labs. The idea seems sense, i.e., downstream teams should be able to defend themselves before critical vulnerabilities are fully disclosed. However, a policy is only effective if it consistently reaches all relevant teams.
There are issues with the August series. Who is notified if a security release is deemed state-breaking and important? Which teams are immediately contacted? How soon are validators informed if they need to stop? Who confirms that a patch is in production? What happens if a project has a customized implementation or is understaffed?
KiiChain has openly challenged the disclosure procedure and contended that the event might have been prevented, claiming that downstream chains need notice before to a public update that made the vulnerability simpler to find. As of this writing, Cosmos Labs' complete technical incident report has not yet been released.
That report is important because if a postmortem merely reveals the bug, a multichain ecosystem cannot learn from shared infrastructure failure. When the vulnerability was found, when downstream teams were contacted, when patches were sent, which chains recognized exposure, and when upgrades were finished should all be displayed.
The metric is not “a patch was released,” but how many vulnerable chains were protected before exploitation. That is the difference between a software fix and ecosystem security.
A Warning for the Multichain Future
Getting away with shared modules is not the solution. Multichain development is facilitated by reusable infrastructure.
The takeaway is that shared infrastructure necessitates shared security responsibilities.
Each project that uses a common module should be aware of its version, applicable updates, enabled features, and upgrading path. A dependable downstream registry and a crisis protocol that functions when multiple chains are attacked at once are essential for upstream maintainers.
Additionally, there ought to be a clearer differentiation between security reuse and code repetition. 10 independent audits do not inevitably produce ten independent security boundaries if ten chains import the same component. They might just restate the same guaranty based on the same fundamental premise.
The obvious warning indicators include MANTRA, KiiChain, TAC, and Nesa; the bigger problem is that these networks covertly share the same reliance. Other users are included in Cosmos EVM's documentation, indicating that possible exposure may extend beyond the chains that have previously been impacted.
MANTRA Chain is producing blocks again.
— MANTRA | The EVM L1 for RWAs (@MANTRA_Chain) August 22, 2026
The vulnerability in the Cosmos-EVM module has been fixed, the network has resumed, and no user funds were affected.
Thank you to everyone for your patience throughout the incident.
Review the full history of incident status updates… pic.twitter.com/IDVpw7H7Tp
Coordination speed becomes a security primitive with more shared components. Chain-level independence does not eliminate systemic infrastructure risk if a vulnerability spreads more quickly than the patch.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Mislav Javor Joins Ethlabs to Build Ethereum
- How $900 Bought Control of an $8.5M DeFi Vault
- Yearn Vaults Safe After $8.5M Exploit
- Maya Protocol Exploit Drains $1.7M in CACAO
- CFTC Closes FTX Cases Against Ellison & Wang with Trading Bans
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.