Cosmos Labs has urged chains using its Cosmos EVM software to halt validator operations as engineers respond to an ongoing security incident affecting users of the shared Ethereum-compatible infrastructure.
The organization issued the emergency advisory on August 25, saying its security and engineering teams were “proactively addressing” the incident. Cosmos Labs recommended that Cosmos EVM chains it is communicating with ask validators to halt their networks while the investigation continues.
Cosmos Labs has not yet disclosed the total amount of assets affected, identified every vulnerable chain or provided a complete technical explanation of the latest attacks. It said a detailed incident report would be released once the situation is resolved.
The warning follows security incidents involving MANTRA Chain and TAC, both of which use Cosmos EVM components and halted their networks after detecting exploits during the past several days.
The shared infrastructure creates potentially broader implications than a vulnerability isolated to one blockchain because Cosmos EVM provides Ethereum Virtual Machine compatibility that multiple independent Cosmos SDK chains can integrate.
MANTRA and TAC Both Halt Networks After Exploits
MANTRA stopped its Layer 1 blockchain on August 20 after detecting an incident involving its Cosmos EVM module.
The network said two MANTRA-managed wallets were affected but reported no impact to user, exchange or partner funds. After roughly 30 hours offline, validators resumed block production at approximately 5:30 a.m. UTC on August 22 using the patched v8.4.0 software release. No blockchain rollback was required and user balances remained unchanged.
TAC subsequently detected another exploit on August 22. The TON-connected EVM network said an attacker exploited a vulnerability in the Cosmos EVM precompile layer and accessed a single account before validators stopped the blockchain at block 24,671,475. TAC explicitly said the defect was in the shared Cosmos EVM module rather than TAC-specific code.
Initial TAC disclosures did not specify the amount stolen. Later reports have claimed approximately 29.86 billion TAC worth around $7.5 million was taken, although that figure has not yet been established through a complete official postmortem.
The incidents explain why Cosmos Labs is now recommending defensive halts across potentially exposed networks rather than addressing each exploit independently.
Earlier Cosmos EVM Flaw Cost SagaEVM About $7 Million
The episode is particularly significant because Cosmos EVM already experienced a critical security failure earlier this year.
In January, an attacker exploited SagaEVM and extracted approximately $7 million. Cosmos Labs subsequently disclosed security advisory ASA-2026-002 in March, describing a critical vulnerability involving incorrect state handling during nested execution through the ICS20 precompile.
The vulnerable code had been introduced upstream in July 2024. Cosmos Labs was notified after the January 21 SagaEVM attack and coordinated remediation with affected networks.
The March advisory classified the vulnerability as critical and said Cosmos EVM implementations containing the ICS20 precompile were affected. Version 0.6.0 contained the patch, and Cosmos Labs said at disclosure that all known affected chains had either upgraded or applied mitigations.
Whether the latest incidents represent exploitation of precisely the same underlying vulnerability, an incomplete mitigation or a related weakness in the precompile architecture has not yet been definitively established by Cosmos Labs. Current reporting has connected the events to the earlier ICS20 issue, but the organization’s promised postmortem will be needed to establish the exact relationship.
That distinction is critical. If previously patched software is being exploited through a new attack path, Cosmos EVM may require another protocol-level fix. If affected chains failed to correctly deploy earlier mitigations, the incident would instead highlight the difficulty of coordinating emergency security upgrades across independent blockchain networks.
For now, Cosmos Labs’ recommendation is unusually aggressive: potentially exposed validators should stop producing blocks rather than risk additional exploitation.
With MANTRA already forced into a 30-hour outage and TAC subsequently halting, the priority has shifted from maintaining uptime to determining how broadly the shared vulnerability extends — and ensuring another Cosmos EVM chain is not exploited before the root cause is fully contained.
