One Cosmos EVM Bug Has Now Hit Four Chains
Cosmos Labs confirmed an active security incident in its Cosmos EVM module and advised connected chains to have validators halt while its engineers work through a fix.
The weakness sits in the ICS20 precompile: state changes made during nested EVM calls were not carried back into the outer transaction, letting an attacker spend the same balance more than once. It drained the Saga network of about $7 million back in January, and a permanent fix shipped publicly as part of v0.6.0.
Not every chain upgraded in time. This month the same class of bug hit TAC, which lost about $7.5 million and halted its chain, alongside KiiChain and MANTRA, all running the shared Cosmos EVM module. MANTRA said user balances were left intact after it resumed blocks on a patched build.
That makes it one of the year's most repeated infrastructure exploits: a single upstream vulnerability, disclosed and patched months ago, still cascading across every chain that had not yet pulled the update.
Partner Offers | Get Your Instant BTC Cashback | Your Gateway To Crypto | Arcus Private Whitelist