Cosmos requests validators to ‘halt their chains’ after EVM breach: 148.3M KII lost
Multiple Cosmos EVM chains faced different levels of disruption as teams worked to contain the shared security issue.
Cosmos experienced an active Ethereum Virtual Machine (EVM) security incident impacting its modules. This incident forced affected networks to prioritize containment as investigators assessed the underlying issue.
In response to the threat, Cosmos Labs urged validators on affected EVM chains to halt operations, restricting activity while security teams assessed the vulnerability.
That response reduced further exposure by stopping uncertain transactions from continuing across networks potentially linked to the affected module.

However, the incident’s impact remained unclear because Cosmos had not disclosed the affected chains, potential losses, or the vulnerability’s technical details. This left the immediate focus on containment rather than measuring financial damage.
With validators coordinating network pauses, attention then shifted toward identifying the root cause and determining which chains required remediation before safely restoring normal operations.
Cosmos incident disrupts connected chains
As the Cosmos EVM issue spread, three chains disclosed impact levels of damage and recovery protocols. KiiChain stood out as it suffered the most impact, losing 148.3 million KII across 18 different attacks before validators halted the network.
In a postmortem report, the chain reported that more than half the stolen funds can be recovered since they did not leave the chain. This accounted for 80.7m KII, or 54% of the exploited tokens.
The chain also shifted the blame to Cosmos EVM, claiming that the vulnerability was in Cosmos code rather than KiiChain code. This is because KiiChain ran on the Cosmos EVM module without any modification.
Meanwhile, TAC had the advantage of limiting exposure, shutting down at block number 24,671,475. As a result, validators halted all operations after attackers drained one account, preventing further exploitation.
Elsewhere, MANTRA was able to avoid exposing its users to losses when it paused operations for 30 hours and deployed Cosmos EVM version 8.4.0.

However, restarting operations after deployment demonstrated that patching can allow safe resumption of operations. Still, KiiChain remains offline, and therefore the ability to resume operations will depend upon a coordinated validator update.
The underlying cause remains undisclosed
Even as some chains recover, the incident remains open because the failure inside the shared Cosmos EVM module is still unresolved. MANTRA restarted with Cosmos EVM version 8.4.0, yet other networks remain halted while teams coordinate their next steps.
Therefore, individual disclosure of losses remains the primary method of measuring the damage done. These disclosures identify unauthorized transactions to shared EVM modules. Yet, they do not provide a complete understanding of the technical failures.
While those reports trace unauthorized activity to shared EVM code, they do not establish the full technical failure. Until Cosmos Labs publishes the incident report, chains can patch known exposure but cannot confirm that every related weakness is fixed.
Final Summary
- The Cosmos EVM incident forced network halts, with KiiChain losing 148.3 million KII across 18 attacks.
- MANTRA resumed after patching, but the root cause and full Cosmos EVM exposure remain undisclosed.