Author: Gu Yu, ChainCatcher
Over the past few days, the Cosmos ecosystem experienced an avoidable "security disaster." Blockchains like MANTRA, TAC, KiiChain, and Nesa, which utilize the Cosmos EVM module, were successively attacked. Protocol reserve tokens from the treasury wallets on each chain were stolen in bulk by hackers and quickly dumped, causing tokens like KII, TAC, and NES to plummet by over 90% within hours, resulting in heavy losses for numerous token holders.
Initially, the market did not notice the common factor behind this series of incidents—that they all involved Cosmos-based blockchains. After all, hacker attacks in the crypto market have become commonplace. However, it wasn't until yesterday that the market realized this series of incidents all originated from the v0.7.2 upgrade code released by Cosmos Labs on GitHub on August 19th.

On that GitHub page, Cosmos Labs wrote: "This release contains important security fixes. We recommend all chains upgrade to this patched version as soon as possible using a coordinated upgrade. This release is disruptive." The urgency in the wording reflects the severity of the vulnerability.
However, Cosmos Labs' actions were perplexing: they made the security patch completely public but did not simultaneously send any private warnings or mandatory upgrade notifications to the project teams relying on this module. This was akin to hanging the key to the treasury in a public square with a sign saying "Please take it quickly," giving malicious actors ample time to study and execute attacks.
"If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will always happen. The measure of enterprise infrastructure is everything after the vulnerability occurs: who is exposed, who gets warned, who gets the patch, and whether customers or attackers move first. We need the full post-mortem from Cosmos Labs. But there's no sugarcoating this: the coordination failure was severe," said developer @justde.
KiiChain, which was attacked, also posted directly criticizing Cosmos Labs for its irresponsible behavior, stating that this incident "could have been avoided."
KiiChain stated that when Cosmos Labs made the announcement on Friday, they bundled the fix with a batch of previously handled unrelated issues. At that time, they did not treat it as an extremely urgent matter, like a severe vulnerability that could lead to permanent loss of funds. They also did not recommend pausing all chains.
KiiChain also revealed the specific attack principle of the vulnerability. The attack requires the simultaneous presence of three upstream defects in the Cosmos EVM module to be effective: an underflow occurring when writing delegated balances back to EVM during staking precompilation, along with two other yet-to-be-disclosed vulnerabilities. KiiChain's specific code did not participate in this attack. All Cosmos EVM chains with vested accounts enabled share the same risk.
More lamentably, such attacks continued as late as the evening of the 24th. The Nesa project team immediately issued an announcement and took measures to halt the blockchain. "We have detected malicious activity exploiting the Cosmos EVM vulnerability on L1 and are taking steps to contain the impact. We have acted swiftly and will bring services back online after applying software fixes and further remediation measures to ensure safe operations."

By then, the Nesa token had already plummeted by over 94%, dropping from its previous price of $0.22 to $0.011. Very few projects can recover normal operations from such a steep decline.
However, the fact that the project team did not take proactive measures to mitigate the risk even after multiple Cosmos EVM security incidents and at least 2 days after the issue was exposed still indicates a severe lack of risk and responsibility awareness within their technical team.
As early as the 21st, MANTRA publicly stated that they had identified the root cause of the incident, which was limited to the Cosmos EVM module on the MANTRA Chain.

As more discussions erupted, Cosmos Labs' public response statement arrived belatedly: "An ongoing security incident is affecting users of the Cosmos EVM module. The security and engineering teams at Cosmos Labs have proactively responded to this event. We have advised Cosmos EVM chains that have been in contact with us to request their validators pause their chains."
However, it was too late. Criticism and disappointment from various quarters flooded social media. "They maintain a shared EVM module that dozens of chains depend on, but when a critical precompilation vulnerability emerged, they didn't proactively issue patches through main channels, provide clear PoCs, or coordinate deployment guidance. These chains are downstream of your code. Your job is to release security patches + deployable PoCs quickly so the entire ecosystem can upgrade cleanly. Instead, we got silent upstream disruption, with each team struggling alone," said developer @justde.
Currently, the Cosmos token ATOM still has a market cap of $800 million, ranking 68th among all tokens, but it has fallen more than 95% from its peak.
Its ecosystem development has also continued to suffer setbacks over the past few years. In just the past six months, Cosmos ecosystem projects like Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation have announced they are ceasing operations. Projects like Secret Network and Noble have announced they are abandoning the Cosmos ecosystem, opting to build their own Layer1 or migrate to the Ethereum ecosystem.
This series of thefts undoubtedly further magnifies the deep-seated flaws in Cosmos's underlying code security audits, cross-chain coordination mechanisms, and emergency response systems.
Security vulnerabilities themselves might be inevitable, but the unbelievable logic of "publishing a patch without informing downstream" and various "amateurish" performances are enough to send chills down the spine of all builders.






