Cosmos Discloses Critical Patch Without Warning, Hackers Drain Multiple Project Treasuries
chaincatcherOver the past few days, the Cosmos ecosystem has witnessed an avoidable "security disaster." MANTRA, TAC, KiiChain, Nesa, and other blockchains using the Cosmos EVM module were attacked in succession. Hackers stole protocol reserve tokens from each chain's treasury wallets in bulk and quickly dumped them, causing tokens like KII, TAC, and NES to plummet over 90% within hours, inflicting heavy losses on many holders.
Initially, the market did not notice the common factor behind this series of incidents—all were Cosmos-based blockchains, as hacking attacks in the crypto market have long been commonplace. It was not until yesterday that the market realized these incidents all stemmed from the v0.7.2 upgrade code released by Cosmos Labs on GitHub on Aug. 19.

Cosmos Labs wrote on the GitHub page: "This release contains important security fixes. We recommend all chains upgrade to this patch version as soon as possible using a coordinated upgrade. This release is groundbreaking." The urgent tone reflects the severity of the vulnerability.
However, Cosmos Labs' actions are puzzling: they made the security patch fully public but did not send any private warnings or mandatory upgrade notifications to the project teams relying on the module. This is equivalent to hanging the treasury keys in a public square with a sign saying "Please take quickly," giving malicious actors ample time to study and carry out attacks.
"If attackers can read GitHub, downstream teams need something better than GitHub. Vulnerabilities will always happen. Enterprise infrastructure is judged by everything that happens after a vulnerability: who was exposed, who was warned, who got the patch, and whether customers or attackers acted first. We need a full post-mortem from Cosmos Labs. But this can't be sugarcoated: the coordination failed badly," said developer @justde.
KiiChain, which was attacked, also directly criticized Cosmos Labs' irresponsible behavior, stating that the incident "could have been avoided."
KiiChain said that when Cosmos Labs released the announcement on Friday, they bundled the fix with a batch of unrelated issues that had been handled privately. They did not treat it as an extremely urgent matter, as one would for a serious vulnerability that could lead to permanent loss of funds. They also did not recommend that all chains be paused.
KiiChain also disclosed the specific attack mechanism. The attack required three upstream flaws in the Cosmos EVM module to be present simultaneously: an underflow when writing back the delegated balance to the EVM during staking precompile, and two other undisclosed vulnerabilities. KiiChain's specific code was not involved in this attack. All Cosmos EVM chains with vesting accounts enabled face the same risk.
More dishearteningly, such attacks were still ongoing until the evening of the 24th. The Nesa project team immediately issued an announcement and took measures to pause the blockchain. "We have identified malicious activity exploiting the Cosmos EVM vulnerability on L1 and are currently taking steps to contain the impact. We have acted swiftly and will restore services after applying software fixes and further remediation to ensure secure operations."
By then, the Nesa token had already plummeted over 94%, from $0.22 to $0.011. Very few projects can recover from such a crash and resume normal operations.
However, the project team did not proactively take measures to mitigate risks even after multiple Cosmos EVM security incidents and at least two days after the issue was exposed. This still indicates a serious lack of risk and responsibility awareness in the project's technical team.
As early as the 21st, MANTRA publicly stated that the root cause had been identified and was limited to the Cosmos EVM module of MANTRA Chain.

As discussions intensified, Cosmos Labs' public response statement was belated: "The ongoing security incident affects users of the Cosmos EVM module. Cosmos Labs' security and engineering teams have proactively responded to this incident. We have advised Cosmos EVM chains that have contacted us to request their validators to pause their chains."
But it was too late; criticism and disappointment from all sides flooded social media. "They maintain a shared EVM module that dozens of chains depend on, but when a critical precompile vulnerability emerged, they did not proactively release a patch through main channels, did not provide a clear PoC, and did not offer coordinated deployment guidance. These chains are downstream of your code. Your job is to quickly release security patches and ready-to-deploy PoCs so the entire ecosystem can upgrade cleanly. Instead, we got silent destruction from upstream, and each team was left to struggle alone," said developer @justde.
According to RootData, the market cap of Cosmos token ATOM is still $800 million, ranking 68th among all tokens, but it is down over 95% from its peak.
Its ecosystem development has also suffered setbacks over the past few years. In the past six months alone, Cosmos ecosystem projects such as Neutron, Mars Protocol, Pryzm, Leap Wallet, and Cosmostation have announced they are ceasing operations, while Secret Network, Noble, and others have announced they are abandoning the Cosmos ecosystem to build their own Layer 1 or migrate to the Ethereum ecosystem.
This series of thefts undoubtedly magnifies Cosmos' deep flaws in underlying code security auditing, cross-chain coordination mechanisms, and emergency response systems.
Security vulnerabilities themselves may be unavoidable, but the absurd logic of "public patch without notifying downstream" and the various "amateurish" performances are enough to chill all builders.
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.