Cosmos EVM module security incident: Cosmos Labs urges chain halts after renewed exploits

Cosmos Labs warned on Aug. 24, 2026 that an active security incident is targeting chains built with its Cosmos EVM module, a plug-and-play layer enabling Cosmos SDK chains to run EVM-compatible execution. Cosmos Labs told affected validators to stop block production and said it will publish a full incident report once the situation is contained. The warning follows a 2026 pattern of Cosmos EVM module-related breaches: - January 2026: SagaEVM exploit drained an estimated $7 million across 15 module-linked chains (only one ultimately exploited). - Aug. 20–22: MANTRA Chain breach forced a ~30-hour halt before emergency patches restored operations. - Aug. 22: TAC was hit as attackers exploited precompile-layer vulnerabilities to move funds without minting new tokens. Cosmos Labs’ current advisory suggests either a broader systemic weakness across shared codebases or attackers finding generalized paths to exploit the Cosmos EVM module. The incident trail points back to ASA-2026-002, disclosed in March 2026. That flaw involved the ICS20 precompile, which supports cross-chain token transfers in the Cosmos ecosystem. The reported core issue was incorrect state handling during nested EVM execution, potentially allowing manipulation of balances and ownership tracking. A March patch was deployed with ecosystem stakeholders, but the August re-emergence raises the question of incomplete fixes or new exploit routes through related code. Cosmos Labs has not yet released the full list of affected chains or the total value at risk.
Bearish
This is a direct, chain-level security warning involving the Cosmos EVM module, with Cosmos Labs urging affected validators to stop networks. In past crypto market behavior, confirmed or suspected exploit waves typically trigger immediate risk-off positioning: liquidity thins, token prices tied to affected ecosystems often sell off, and traders price in longer maintenance times and governance/patch uncertainty. The article cites prior high-impact incidents in 2026 (SagaEVM estimated $7M loss, plus MANTRA Chain and TAC breaches in August). The recurrence within the same module increases the odds that investors will treat this as a systemic risk rather than an isolated smart-contract failure. In the short term, traders may expect volatility around validators, relayers, and any tokens used for cross-chain transfers linked to ICS20-style flows. In the long term, market sentiment will depend on whether Cosmos Labs can provide a definitive affected-chain list, a robust patch, and clear remediation timelines; otherwise, repeated exploit narratives can keep a persistent discount on Cosmos-adjacent assets.