Cosmos Labs Warns of Security Incident Affecting Cosmos EVM Module Users

iconCryptoBriefing
Share
AI summary iconSummary
Cosmos Labs warned on August 24 of a security incident impacting chains using the Cosmos EVM module. Validators were told to halt operations while the team works to contain the issue. The attacks seem tied to a flaw in the ICS20 precompile, which is part of the Cosmos IBC framework. A patch was issued in March 2026, but new exploits suggest ongoing contract security risks. Previous incidents in 2026, including a $7 million SagaEVM breach, highlight the need for stronger contract security across the ecosystem. A full report will follow once the situation is resolved.

Cosmos Labs disclosed on August 24 that an active security incident is targeting chains built with its Cosmos EVM module, a plug-and-play layer that gives Cosmos SDK chains compatibility with the Ethereum Virtual Machine. The team’s advice to affected validators was blunt: stop your networks.

Cosmos Labs said it plans to release a full incident report once the situation is contained.

A pattern of exploits in 2026

This isn’t the first time the Cosmos EVM module has been at the center of a security scare this year. In January 2026, the SagaEVM exploit drained an estimated $7 million. That attack affected 15 chains that used the module, though only one was ultimately exploited.

Advertisement

The more immediate precursors, however, are even more troubling. MANTRA Chain experienced a breach between August 20 and 22, forcing a 30-hour halt before operations resumed after emergency patches were applied. TAC was hit on August 22 as well, with attackers exploiting precompile-layer vulnerabilities that allowed unauthorized fund transfers without needing to mint new tokens.

Two days later, Cosmos Labs issued its ecosystem-wide warning. The timing suggests that either the MANTRA and TAC incidents revealed a broader, systemic weakness, or that attackers found a way to generalize their exploit across multiple chains sharing the same codebase.

The vulnerability trail leads back to March

The current wave of attacks appears connected to a critical vulnerability catalogued as ASA-2026-002. That flaw, disclosed in March 2026, involved the ICS20 precompile, a component that handles cross-chain token transfers within the Cosmos ecosystem. The core issue was incorrect state handling during nested EVM execution, a bug that could allow an attacker to manipulate how the system tracks balances and ownership during complex transactions.

A patch was developed and deployed in March through a collaborative effort involving multiple stakeholders in the Cosmos ecosystem. But the re-emergence of exploits in August raises an uncomfortable question: was the patch incomplete, or have attackers found new pathways through related code?

What’s at stake for the ecosystem

Cosmos Labs has not yet disclosed the full list of affected chains or the total value at risk. The advisory effectively asks chains to halt block production until Cosmos Labs provides further guidance.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.