3 Cosmos Chains Just Froze Mid-Block: Attackers Are Draining Accounts Right Now

Attackers are actively draining wallets across the Cosmos ecosystem, and three networks have already confirmed they were hit.

Cosmos Labs issued an emergency alert confirming a live security incident targeting the Cosmos EVM module, the same infrastructure layer powering a growing number of EVM-compatible chains built inside the Cosmos ecosystem. The advisory was blunt: any chain in contact with Cosmos Labs should instruct validators to halt block production immediately.

Who Got Hit and How Bad

Two chains did not wait around. KiiChain and TAC both froze their networks after confirming attackers had successfully drained user accounts. Freezing a chain mid-block is a last-resort move. It signals the team believes continuing block production would allow further theft, and that the attack vector is not yet closed.

MANTRA also confirmed exposure but took a different path. Rather than staying frozen, it restarted its mainnet, suggesting its team believes it has contained the threat or patched the vulnerability fast enough to resume operations safely.

All three chains traced their incidents back to the same root cause: the Cosmos EVM module.

Why This Is Bigger Than Three Chains

The Cosmos EVM module is not a niche component. It is the bridge that lets Cosmos-native chains speak the language of Ethereum, allowing developers to deploy Solidity smart contracts and attract EVM-native users and liquidity. If the exploit lives inside that shared module, the attack surface does not stop at three chains.

Any Cosmos chain running EVM compatibility needs to be asking one question right now: are we next?

Cosmos Labs has not yet disclosed the specific nature of the vulnerability, which means the broader ecosystem is operating with incomplete information during an active incident. That is the most dangerous window in any exploit: the gap between discovery and a verified fix.

What Crypto Holders Need to Watch

If you hold assets on any Cosmos EVM-compatible chain, the move right now is simple: check whether your chain has issued a security advisory, and if validators have been asked to halt, treat that as a signal to avoid transactions until the chain is declared safe.

Watch for Cosmos Labs to release a post-mortem identifying the exact exploit. That disclosure will tell the market how deep this goes and which chains remain at risk. Until then, the safest assumption is that the blast radius is wider than three networks.

The ATOM ecosystem has momentum. This incident is a reminder that shared infrastructure means shared risk.