- Cosmos Labs has told any public chain running its Cosmos EVM module below v0.6.2 or v0.7.2 to stop producing blocks and apply the patch.
- Six networks were drained through the same accounting flaw, including MANTRA, TAC and KiiChain, for $5.7m between them. Cosmos Labs says it contacted around 40 chains it believed could be exposed, and now accepts it wrongly cleared the bug months before the attacks.
- Halting freezes in place. They aren’t gone, but they can’t be moved, sold or withdrawn until the fix lands and the chain restarts.
Blockchains are built on the promise that they never stop. The team maintaining a widely used piece of Cosmos software has now told around 40 of them to stop anyway, after the same flaw was used to drain $5.7m from six separate chains.
When a chain halts, your tokens stay exactly where they are and stop moving. Nothing has been stolen from you, but nothing can be sent, swapped or withdrawn until the operators ship the patch and start the chain up again. That is a far better outcome than being drained. It is still your money out of reach for as long as the repair takes, and while Cosmos Labs has named the six chains that were emptied, it hasn’t published the full list of the roughly 40 it contacted, so holders on smaller chains still can’t easily check where theirs sits.
What we know, and where it comes from
The halt instruction came first. The Defiant reported the advisory went up at 11:19 a.m. New York time and quoted it directly: teams should “immediately halt the blockchain and upgrade it to include the patches in those releases.”
The scale came afterwards, in a security postmortem from Cosmos Labs reported by CryptoSlate. It puts the number of exploited networks at six, names MANTRA, TAC and KiiChain among them, and splits the stolen funds into about $2.87m moved out through decentralised exchanges and roughly $2.85m through centralised ones. Accounts linked to the centralised side have since been frozen, which is the one route by which some of that money might come back.
Cosmos Labs has since said plainly that it got the severity call wrong. The Block reports the team accepts it wrongly cleared the accounting bug, which had been logged around four months earlier and assessed as less serious than it turned out to be. Four months sit between a bug being catalogued and six chains being emptied.
MANTRA, which lost $3.6m and so accounts for most of the $5.7m total, disputes how the fix reached chains at all. Its account, also via The Block, is that the patch was published roughly 20 hours before the attack began and did not identify the flaw it closed. On that version a chain team would have had to infer both the urgency and the reason from a release that looked routine, which is a separate question from whether a fix existed. The two timelines have not been reconciled in public, and neither can be settled from outside.
The practical instruction still depends on a version number. A chain team needs to know whether it is running something below v0.6.2 or v0.7.2, and a holder needs to know whether their chain is one of them.
One module, many separate blockchains

Cosmos is not a single blockchain in the way Ethereum is. It is a set of building blocks that teams use to launch their own independent chains, each with its own , its own token and its own governance. The Cosmos Hub and its ATOM token are one chain among many.
The Cosmos EVM module is one of those building blocks. It bolts on the ability to run Ethereum-style , so a Cosmos chain can host apps written for Ethereum without rebuilding them. Dozens of projects took that component off the shelf rather than writing their own, which is exactly what shared infrastructure is for.
The flip side arrives on a day like this. A flaw in a shared module is inherited by everything that imported it, and each of those chains is run by a different team with different response times and different levels of attention. There is no central operator to push a fix out to all of them at once. Every chain has to notice, decide and act on its own. The figure of 40 contacted networks is a reasonable measure of how far one line of borrowed code travelled.
We have been here already this year. When MANTRA’s chain went offline after an exploit, its team pointed at shared Cosmos EVM code as the cause, and at the time it read as one project’s misfortune. It wasn’t: MANTRA is now confirmed as one of the six, and the postmortem describes an unprivileged wallet moving around 720.9 million tokens on 20 August out of two addresses that had authorised nothing, with no validator, administrator, governance or multisig keys compromised. That last detail is what makes this a software fault rather than a stolen-keys story.
What a halt does to your holdings
Stopping a chain means the validators stop producing new blocks. Balances are preserved, transactions already confirmed stay confirmed, and the ledger simply sits still. Anything you try to do afterwards fails, because there is nothing to record it.
For a UK holder the effect depends on where the tokens sit. In a wallet, they are visible and immovable until the chain resumes. On an exchange, you may not see a halt at all beyond a notice that deposits and withdrawals for that token are suspended, which exchanges typically do quickly when a network stops. Our guide to withdrawals covers what is worth doing, and not doing, when a route out is closed for reasons outside your control.
The list, and the part still missing
Cosmos Labs has now named the six chains that were drained and says 13 other potentially exposed networks have patched. That is more than holders had on Tuesday, and it is the right way round: counting the chains that have upgraded answers the question without handing anyone still hunting a target list of the ones that haven’t.
A count is not a list, though. Six named and 13 counted leaves roughly 20 of the 40 contacted networks unaccounted for in public. For a holder on a smaller Cosmos chain, the only thing that resolves it is a statement from that chain’s own team, and plenty of them have not made one.
What to watch
Statements from the individual chains that haven’t spoken yet, confirming which version they run and whether they have restarted. Those, not the advisory or the postmortem, are what a holder can actually use.
Then the total. The $5.7m is Cosmos Labs’ own figure and it covers the six chains identified so far, which means it can only really move in one direction as the rest of the 40 are checked.
The remaining argument is about sequence rather than cause. Cosmos Labs has accepted it misjudged the bug, so what is still open is when each chain was told, what the release notes said, and whether other operators recognise MANTRA’s account of a patch landing 20 hours before the attack with no indication of what it fixed. The teams that imported that module are entitled to a timeline they can check against their own records.