Cosmos Labs disclosed on August 24 that an active security incident is targeting chains built with its Cosmos EVM module, a plug-and-play layer that gives Cosmos SDK chains compatibility with the Ethereum Virtual Machine. The team’s advice to affected validators was blunt: stop your networks.
Cosmos Labs said it plans to release a full incident report once the situation is contained.
A pattern of exploits in 2026
This isn’t the first time the Cosmos EVM module has been at the center of a security scare this year. In January 2026, the SagaEVM exploit drained an estimated $7 million. That attack affected 15 chains that used the module, though only one was ultimately exploited.
The more immediate precursors, however, are even more troubling. MANTRA Chain experienced a breach between August 20 and 22, forcing a 30-hour halt before operations resumed after emergency patches were applied. TAC was hit on August 22 as well, with attackers exploiting precompile-layer vulnerabilities that allowed unauthorized fund transfers without needing to mint new tokens.
Two days later, Cosmos Labs issued its ecosystem-wide warning. The timing suggests that either the MANTRA and TAC incidents revealed a broader, systemic weakness, or that attackers found a way to generalize their exploit across multiple chains sharing the same codebase.
The vulnerability trail leads back to March
The current wave of attacks appears connected to a critical vulnerability catalogued as ASA-2026-002. That flaw, disclosed in March 2026, involved the ICS20 precompile, a component that handles cross-chain token transfers within the Cosmos ecosystem. The core issue was incorrect state handling during nested EVM execution, a bug that could allow an attacker to manipulate how the system tracks balances and ownership during complex transactions.
A patch was developed and deployed in March through a collaborative effort involving multiple stakeholders in the Cosmos ecosystem. But the re-emergence of exploits in August raises an uncomfortable question: was the patch incomplete, or have attackers found new pathways through related code?
What’s at stake for the ecosystem
Cosmos Labs has not yet disclosed the full list of affected chains or the total value at risk. The advisory effectively asks chains to halt block production until Cosmos Labs provides further guidance.

