Cosmos Labs Urges EVM Chains to Halt as Shared Bug Drains Three Networks
Cosmos Labs recommended that EVM chains built on its shared stack halt operations after a vulnerability drained three networks. KiiChain, one of the affected chains, reported losing 148 million tokens, and the halt advisory came six days after a patch shipped without a public security advisory.
A shared vulnerability in the Cosmos EVM stack means many chains may be exposed at once, not just a single network. This incident can undermine trust in the ecosystem and highlights the critical need for coordinated security disclosure across interconnected chains.
KiiChain stated that two of the three underlying defects remain unfixed upstream. The delay between the patch release and the public advisory may have left other chains unaware of the critical risk.
rss · The Defiant · · Single source
Background, discussion, and references
Market impact
As a security exploit in shared Cosmos EVM infrastructure, the incident can strain liquidity on affected chains and may heighten caution toward Cosmos-based EVM chains. With tokens already drained, operations halted, and defects not fully fixed, trading and liquidity conditions for listed assets on these chains could be disrupted until the situation is resolved.
Background
Cosmos is an ecosystem of interoperable blockchains built with the Cosmos SDK, using CometBFT consensus and IBC for communication. EVM-compatible chains in this ecosystem, such as KiiChain, often rely on shared modules like the Cosmos EVM/Ethermint library, so a bug in that shared code can affect multiple networks simultaneously.
References
Tags
#security#exploit#cosmos#evm#cross-chain