Shared Software Flaw Prompts Emergency Validator Shutdowns
An ongoing security threat affecting a shared smart contract framework has forced multiple blockchain networks to abruptly freeze their operations. On August 25, Cosmos Labs issued an urgent advisory instructing affected networks to suspend validator block production while engineers address an active incident impacting its Ethereum Virtual Machine (EVM) component, according to Crypto.news.
The underlying Cosmos EVM module serves as a critical bridge, allowing independent Cosmos SDK chains to execute Ethereum-compatible smart contracts. Because the software stack is shared, a defect in a common module inadvertently exposes multiple individual networks running those specific configurations to the same potential exploits.
Cosmos Labs has directed affected teams to coordinate with their validator sets to halt decentralized proof-of-stake operations. This emergency measure prevents new transactions from settling and temporarily blocks decentralized applications, regular transfers, and withdrawals while developers distribute a viable patch.
Mounting Ecosystem Exploits The coordinated halt follows a string of unauthorized asset withdrawals on at least three distinct networks. KiiChain reported that a malicious actor drained exactly 148,326,583.15 KII tokens across 18 separate transactions on August 22, according to BeInCrypto. The network’s validators successfully froze operations at block 9,355,723 to prevent further losses.
The attackers reportedly exploited weaknesses tied to balance handling, staking operations, and vesting accounts, subsequently bridging a portion of the stolen assets to the BNB Smart Chain via Hyperlane, according to Crypto.news.

Defending its internal security, the KiiChain team emphasized the external nature of the flaw. “The vulnerability is in Cosmos code, not KiiChain code. It sits in the shared Cosmos EVM module (cosmos/evm), which KiiChain runs unmodified,” the team stated.
TAC, another affected layer-1 network, halted its operations at block 24,671 following a similar exploit in the EVM precompile layer that drained a single account. A security report from industry tracker Odaily, published via KuCoin, subsequently noted that the TAC breach resulted in roughly $7.5 million in stolen assets, highlighting the high financial stakes of the shared infrastructure flaw.
Uneven Impact and Recovery Despite the severe disruption across the broader ecosystem, the practical impact appears uneven. The MANTRA network, which preemptively paused operations on August 20, managed to successfully resume block production after a roughly 30-hour shutdown. According to Crypto.news, the team rebooted the chain from block 17,449,398 utilizing version 8.4.0 without rolling back the network's recorded state.
Providing a critical caveat to the wider market panic, MANTRA confirmed that the anomalous activity was strictly confined to two internally managed wallets and that no user assets were compromised.
The current situation bears a strong resemblance to a previous vulnerability involving the ICS20 precompile. In March, a security advisory warned of incorrect state handling during nested executions, a bug that allowed the same token balance to be utilized repeatedly within one transaction. That specific defect caused an estimated $7 million loss on the SagaEVM network in January.
However, Cosmos Labs has deliberately refrained from publishing technical details, aggregate loss calculations, or a formal confirmation that a single exact vulnerability links all three recent attacks. This cautious approach is standard practice designed to shield remaining unpatched chains from further exploitation while a comprehensive incident report is prepared.


