148M Tokens Gone: Three EVM Chains Drained and Two Bugs Are Still Live Right Now
Three EVM chains built on Cosmos infrastructure were drained through a shared vulnerability, and the patch that was supposed to fix it shipped six days before anyone was told it existed.
KiiChain, one of the three networks hit, confirmed it lost 148 million tokens in the incident. The chain also dropped a detail that should alarm every developer and holder in the Cosmos ecosystem: two of the three underlying defects that enabled the attack remain unfixed at the upstream level. The patch addressed one vulnerability. The other two are still open.
The Silent Patch Problem
This is where the story gets worse. Cosmos Labs shipped the fix without a security advisory. No public warning. No coordinated disclosure. No heads-up to chains running the vulnerable code. Six days passed between the patch going live and any formal recommendation to halt operations.
In crypto security, six days is a lifetime. Sophisticated actors monitor open-source repositories. A fix merged without explanation is effectively a neon sign pointing at the exact line of code that was broken. Any attacker who spotted the patch and reverse-engineered it had nearly a week to move before affected chains knew they were exposed.
This is the disclosure failure that the industry keeps repeating, and projects keep paying for it in nine and ten-figure losses.
What Is Actually Happening Right Now
Cosmos Labs has now urged EVM-compatible chains in its ecosystem to halt. That recommendation is not a patch. It is a pause button while the remaining two vulnerabilities sit unresolved upstream. Chains that comply are protected by downtime. Chains that stay live are running on incomplete fixes against a known attack surface.
KiiChain named the sequence explicitly: the delayed advisory, the incomplete remediation, the token loss. That level of public accountability from a drained chain is rare, and it signals the situation is serious enough that they chose transparency over optics.
What Holders and Developers Need to Watch
If you hold tokens on any EVM chain in the Cosmos ecosystem, the immediate question is whether your chain has halted or confirmed it is not running the vulnerable code. A chain that stays operational without that confirmation is a risk you are holding right now.
For developers, this is a stress test of Cosmos's shared infrastructure model. The same interoperability that makes the ecosystem powerful means a bug in a shared library becomes everyone's problem simultaneously.
Watch for two things: the upstream patch timeline for the remaining two vulnerabilities, and whether any additional chains report losses they have not yet disclosed. In incidents like this, the first number is rarely the final number.