Community Trust ScoreVerified
A silent patch. A public disclosure. And then $16.5 million gone.
Cosmos Labs is taking serious heat after a bug in its Cosmos EVM module hit four blockchains — MANTRA, TAC, KiiChain, and Nesa — and the way the developer handled the whole situation has people furious. The patch went out quietly last week. No warning posted on Cosmos Labs’ official account. No apparent private heads-up to the affected networks, at least not one that’s been confirmed. Two chains halted in time. Two didn’t.
MANTRA and Nesa moved fast. They preemptively stopped their chains, and user funds came out untouched.
KiiChain and TAC weren’t so lucky. On August 22, KiiChain got hit hard — nearly 150 million KII tokens stolen, valued at over $9 million at the time. The attacker liquidated that haul for just $1.6 million in BUSD, which is a brutal number but doesn’t make the breach any less damaging for KiiChain’s community. KiiChain came out swinging at Cosmos Labs afterward, calling the disclosure method too open — basically arguing that going public before affected validators had a real chance to patch created the exact window the attacker used.
TAC lost even more tokens by volume. Three billion TAC tokens were drained from its staking contract, worth roughly $7.5 million. Combined with KiiChain’s losses, that’s over $16 million wiped out in a matter of days from a single underlying vulnerability.
The Disclosure Fight at the Center of This
The technical bug itself is almost secondary now. What’s really driving the anger is the process — or the lack of one.
Cosmos Labs didn’t post a public warning through its official channels before the patch went live. The developer advised affected network validators to halt their chains, but the way that message got out apparently wasn’t tight enough. KiiChain’s position is pretty clear: the disclosure was too open, too fast, and it handed bad actors the information they needed before validators could act. That’s a serious claim, and Cosmos Labs hasn’t responded to questions about whether private disclosures were made before anything went public. That silence isn’t helping.
MANTRA and Nesa’s ability to halt preemptively suggests someone got the message in time — or at least reacted fast enough on their own. But KiiChain and TAC clearly didn’t have that window. Whether that’s a failure of communication from Cosmos Labs, a failure of monitoring on the networks’ end, or both, is still murky.
The broader debate here isn’t new in crypto security circles. Responsible disclosure — the practice of privately warning affected parties before going public with a vulnerability — is pretty much standard in traditional software security. The blockchain space has been slower to adopt consistent norms around it, and incidents like this one keep making that gap obvious.
A Pattern That’s Hard to Ignore
And it’s not the first time. Earlier this year, in January, Saga EVM lost around $7 million in a similar exploit targeting the Cosmos EVM module. That’s three separate incidents now — Saga, KiiChain, TAC — all pointing at the same underlying module. That’s not bad luck. That’s a pattern.
The January Saga incident should have been a loud signal that the Cosmos EVM module needed serious attention and probably a rethink of how patches get communicated to the networks running it. Whether Cosmos Labs made changes after that and whether those changes were enough — unclear. What’s clear is that two more networks just paid a combined $16.5 million price for whatever gaps remained.
Networks using the Cosmos EVM module are probably asking hard questions right now about their own exposure. The “silent patch model,” as critics are calling it, leaves too much to chance. If a validator doesn’t catch the update fast enough, or if the public disclosure happens before private coordination is complete, the exploit window opens. That’s what seems to have happened here.
KiiChain called the loss avoidable. TAC’s community is dealing with three billion tokens gone from a staking contract. Both networks are pushing for better coordination and actual advance notice before any future vulnerability goes anywhere near public.
Cosmos Labs still hasn’t answered whether private disclosures happened at all before the public announcement. That’s the question everyone’s waiting on.
The Saga exploit in January cost around $7 million. KiiChain lost over $9 million in KII tokens, liquidated for $1.6 million in BUSD. TAC lost approximately $7.5 million in token value from its staking contract.
Hub: Cosmos price, news, and analysis
Frequently Asked Questions
Which blockchains were affected by the Cosmos EVM module bug?
Four blockchains were affected: MANTRA, TAC, KiiChain, and Nesa. MANTRA and Nesa halted their chains preemptively and avoided losses, while KiiChain and TAC suffered significant financial damage.
How much did KiiChain and TAC lose in the exploit?
KiiChain lost nearly 150 million KII tokens worth over $9 million, liquidated for $1.6 million in BUSD. TAC lost three billion TAC tokens valued at approximately $7.5 million from its staking contract.
Why It Matters
The incident highlights significant vulnerabilities within the Cosmos ecosystem, raising concerns about security protocols and developer transparency in blockchain networks. As trust is paramount in decentralized finance, the lack of communication from Cosmos Labs could deter potential users and investors, potentially impacting the broader adoption of projects built on the Cosmos platform. Furthermore, this episode may prompt increased scrutiny from regulators and security experts, emphasizing the need for robust risk management practices in the rapidly evolving crypto landscape.
