Via mudrex.com
Cosmos Labs urges Cosmos EVM validators to halt chains amid security incident
The company said it will publish an incident report once the situation is resolved.
Cosmos Labs disclosed on August 24 that an active security incident is targeting chains built with its Cosmos EVM module, a plug-and-play layer that gives Cosmos SDK chains compatibility with the Ethereum Virtual Machine. The team’s advice to affected validators was blunt: stop your networks.
Cosmos Labs said it plans to release a full incident report once the situation is contained.
Cosmos Labs is responding to an ongoing security incident involving users of its Cosmos EVM module and has urged affected Cosmos EVM chains to halt their networks. The company said its security and engineering teams are actively working on the incident.
The scope and nature of the issue remain unclear. A detailed incident report will be released after the situation is resolved, as noted by the team.
The Cosmos EVM ecosystem has faced several security incidents in 2026. The first major incident came in January, when an exploit involving the SagaEVM implementation caused about $7 million in losses.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Cosmos Labs identified 15 chains running code containing the relevant vulnerability, although six had not enabled the affected feature. One chain was exploited, while the others reportedly mitigated the issue before attackers could act.
The ecosystem saw further disruption in August. MANTRA Chain halted block production for roughly 30 hours following an incident involving its Cosmos EVM module. MANTRA said two wallet addresses it managed were affected and that no user funds were exploited. The chain resumed operations on Aug. 22 after deploying a patch.
TAC also halted its chain on Aug. 22 after reporting an exploited vulnerability affecting its Cosmos-based EVM environment and token supply.