Login
Sign Up
Woofun AI reports that a critical security failure within the Cosmos ecosystem triggered a wave of exploits across multiple blockchains, including MANTRA, TAC, KiiChain, and Nesa, following the public release of a patch for the Cosmos EVM module.
The market impact was immediate and severe, with token prices for KII, TAC, and NES plummeting by over 90% within hours as hackers liquidated stolen protocol reserves. This rapid depreciation resulted in heavy losses for token holders who were initially confused by the sudden volatility. The common denominator among these disparate incidents was not immediately apparent to the broader market, as crypto hacks are frequent and often viewed in isolation. It took significant time for observers to connect the dots between these separate attacks and the underlying infrastructure shared by these chains.
The trigger for this cascade was identified as the v0.7.2 update code released by Cosmos Labs on Github on August 19. The release notes described the update as including 'important security fixes' and labeled the release as 'groundbreaking,' urging all chains to perform coordinated upgrades. The urgency in the wording reflected the severity of the vulnerability embedded in the code.
However, the method of dissemination—publicly posting the fix—created a dangerous window of exposure for downstream projects that had not yet patched their systems.
The core controversy lies in the lack of private warnings or mandatory upgrade notices sent to the project teams relying on this module. Critics argued that releasing a high-risk patch publicly without alerting dependent teams was akin to hanging the keys to a vault in a public square with a sign saying 'Please take it quickly.' This approach gave malicious actors ample time to study the patch, reverse-engineer the vulnerability, and execute attacks before legitimate teams could respond. The absence of a private notification channel fundamentally compromised the security posture of the entire ecosystem.
Developer @justde criticized the infrastructure failures, stating, 'If attackers can read Github, downstream teams need something better than Github.' He emphasized that vulnerabilities are inevitable, but the true measure of an enterprise's infrastructure is its post-incident response: who gets exposed, who receives warnings, and whether customers or attackers act first. @justde called for a full post-incident analysis report from Cosmos Labs, concluding that the coordination failed miserably. The incident highlighted a systemic gap in how critical security updates are communicated and deployed across decentralized networks.
KiiChain, one of the attacked projects, issued a statement directly blaming Cosmos Labs for irresponsible behavior, asserting that the incident 'could have been avoided.' KiiChain noted that when Cosmos Labs released the announcement on Friday, they bundled the critical fix with a batch of unrelated issues that had been handled privately earlier. This bundling diluted the urgency, making it appear as if there were no serious vulnerabilities that could lead to permanent loss of funds. KiiChain also revealed the specific attack mechanics, which required three upstream defects in the Cosmos EVM module to occur simultaneously: an underflow when writing back the delegated balance to the EVM during staking pre-compilation, along with two other unpublic vulnerabilities. KiiChain's specific code was not involved; rather, all Cosmos EVM chains that enabled ownership accounts were at risk.
Woofun AI data shows that attacks continued even into the evening of the 24th, prompting the Nesa project team to suspend the blockchain immediately. Nesa announced they had detected malicious activities exploiting vulnerabilities in Cosmos EVM on the L1 layer and were taking steps to contain the impact. By the time of the suspension, the NESA token had already dropped by over 94%, falling from $0.22 to $0.011. Such a sharp decline rarely allows projects to return to normal operation, and the delay in proactive risk mitigation measures indicated serious shortcomings in the technical team's risk awareness and responsibility.
As early as the 21st, MANTRA publicly stated that it had identified the root cause of the issue, which lay solely in the Cosmos EVM module of MANTRA Chain. Despite this early identification, Cosmos Labs delayed its public response until discussions intensified. Cosmos Labs eventually stated, 'The ongoing security incident has affected users of the Cosmos EVM module. Cosmos Labs' security and engineering teams are actively addressing this issue. We have advised Cosmos EVM chains that contacted us to ask validators to pause their chains.' However, this response came too late to prevent widespread damage, leaving many teams to struggle on their own against the exploits.
The broader ecosystem has suffered significant decay, with the ATOM market cap currently at $800 million, ranking it 68th among all tokens. ATOM has dropped by over 95% from its peak, reflecting long-term structural issues. In the past six months alone, Cosmos ecosystem projects such as Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation have announced the suspension of operations.
Additionally, projects like Secret Network and Noble have abandoned the Cosmos ecosystem to build their own Layer 1s or migrate to the Ethereum ecosystem, signaling a loss of confidence in the platform's stability and support.
This series of theft incidents underscores deep-seated flaws in code security audits, cross-chain coordination mechanisms, and emergency response systems within the Cosmos ecosystem. While security vulnerabilities may be inevitable in complex software, the logic of releasing patches publicly without informing downstream parties is fundamentally flawed. The sloppy performance of various teams and the lack of coordinated defense have chilled the hearts of builders, suggesting that without immediate reform, the ecosystem may continue to lose trust and capital.