Key TakeawaysOn August 25, Cosmos Labs issued an emergency directive for all affected Cosmos EVM-based chains to immediately halt validator operations due to an ongoing security breach.A total of 148,326,583.15 KII tokens were stolen from KiiChain through 18 consecutive attacks executed on August 22.The TAC network suspended operations at block 24,671 following the exploitation of a single account through a Cosmos EVM precompile vulnerability.MANTRA successfully restarted its blockchain after approximately 30 hours of downtime, confirming no user funds were compromised.A comprehensive incident report detailing the vulnerability, affected chains, and total financial impact has yet to be released by Cosmos Labs.Several blockchain networks utilizing the Cosmos EVM infrastructure were compelled to suspend their operations in late August 2026 after Cosmos Labs detected an active security compromise affecting its core module.An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains.…— Cosmos Labs (@cosmoslabs_io) August 24, 2026The Cosmos EVM framework serves as an integration layer that enables Cosmos SDK-powered blockchains to achieve Ethereum Virtual Machine compatibility. Due to its shared architecture, any security weakness in the module can impact all networks implementing it.Cosmos Labs announced that both its security specialists and engineering team were working to address the situation. The organization recommended that compromised chains instruct their validators to temporarily cease block production until a security patch could be implemented.KiiChain and TAC Experience Direct Financial DamageKiiChain disclosed that malicious actors successfully extracted 148,326,583.15 KII tokens from user wallets on August 22. The perpetrator executed the exploit 18 consecutive times before network validators successfully halted chain operations at block 9,355,723.According to KiiChain’s analysis, the attack exploited a security flaw related to vesting account mechanisms, staking functions, and balance management within the Cosmos EVM infrastructure. A portion of the compromised assets was subsequently transferred to BNB Smart Chain using the Hyperlane cross-chain bridge.TAC similarly disclosed an exploitation event on August 22. An attacker leveraged a vulnerability in the Cosmos EVM precompile architecture to completely drain a single account before validators successfully stopped the network at block 24,671.Both blockchain projects have verified unauthorized asset transfers occurred. Cosmos Labs has not yet released aggregate loss statistics or verified whether a single threat actor orchestrated both attacks.MANTRA Resumes Operations Following 30-Hour SuspensionMANTRA initiated a network halt on August 20 upon discovering anomalous activity associated with two wallets under project management. Investigation revealed the issue originated from its Cosmos EVM module implementation.Following the deployment of a patched software version, MANTRA orchestrated a coordinated validator restart procedure. The blockchain successfully resumed producing blocks after approximately 30 hours of downtime, restarting operations from a checkpoint at block 17,449,398 while maintaining the chain’s complete transaction history.MANTRA emphasized that user assets remained secure throughout the incident and that only the two affected addresses were part of its internal operational wallet system. A comprehensive technical post-mortem analysis has not yet been made available.The August security incidents follow a previous Cosmos EVM vulnerability related to the ICS20 precompile component. A security bulletin from March 2026 outlined improper state management during nested function execution that permitted identical token balances to be utilized multiple times within a single transaction.That previous security flaw resulted in approximately $7 million in losses on SagaEVM during January 2026. It has not been confirmed whether the August exploits utilized the same code vulnerability or represented a distinct security weakness.Cosmos Labs has committed to publishing a comprehensive incident analysis once the security situation has been fully resolved. The forthcoming report is anticipated to specify the defective component, impacted software versions, and cumulative financial losses across all affected blockchain networks.Pending the official report’s publication, users are advised to actively monitor official network status channels and refrain from executing transactions through unverified third-party interfaces.The post Cosmos EVM Vulnerability Triggers Emergency Shutdowns Across Multiple Chains appeared first on Blockonomi.