CryptoReal
CASE FILE — Sep 2, 2026

KiiChain Exploit: Repeated EVM Module Flaw Leads to Major Token Loss

An identical exploit was successfully executed eighteen times before intervention occurred.

On August 22, an attacker siphoned 148,326,583.15 KII from numerous wallets on KiiChain, deploying the same method against 18 different addresses before the attack was halted.

KiiChain reported that its own staff detected the abnormal outflows and froze the network at block 9,355,723 at 22:50:58 UTC. This action came hours after TAC was compromised via the same vulnerability and two days after MANTRA was first affected.

The stolen tokens were valued at approximately $9.7 million before the exploit, though only part of this sum was actually converted into other assets by the attacker.

A total of 80,728,575.06 KII—representing 54.4% of the stolen tokens—remained on KiiChain, immobilized as soon as validators ceased block production.

The remainder was bridged to BNB Chain via Hyperlane, with most being sold off before KiiChain's incident analysis was even finalized.

By the time the postmortem became public, KiiChain was not only reporting a hack but also criticizing the maintainers of the underlying code for publicly releasing a security patch before informing impacted chains privately—during which time multiple networks were exploited.

If pausing the chain internally stopped more losses than external warnings, what was the actual purpose of the disclosure process?

Credit: KiiChain, The Defiant, Rarma, TAC, Cosmos Labs

KiiChain did not wait for external researchers to label the incident.

During the hours surrounding the network halt, the team issued two Twitter updates.

The first message explained that a bug in the EVM module enabled an attacker to move assets off KiiChain via Hyperlane to BSC, and stated the chain was paused as a containment measure.

The second update, posted later that evening, attributed the problem to the Cosmos EVM module, described the halt as a precaution, and noted that other networks remained unaffected.

That later post also stated: "a detailed incident report will be shared once completed."

That documentation was released promptly. By the following day, KiiChain had issued a comprehensive technical postmortem, detailing the exploit method, affected amounts, wallet addresses, and a recovery strategy.

Contrast this with TAC’s approach: TAC’s initial public comment on its own loss did not specify the attacker, the exploit vector, or the amount.

It was an external forensic thread by Rarma that provided the transaction-level details TAC had omitted.

KiiChain bypassed this gap by publishing its full technical breakdown before outside researchers had to reconstruct the events.

Cosmos Labs’ postmortem quantified the communication timeline: Roughly an hour after learning of TAC’s breach, the team was notified via Slack by KiiChain that a third chain had fallen victim.

KiiChain provided swifter and more comprehensive explanations than the other affected chains. But why did this not result in a smaller financial impact?

The Technical Details Emerge

KiiChain’s report begins by clarifying: The vulnerability was in shared Cosmos code, not in KiiChain’s own codebase.

KiiChain operated an unmodified cosmos/evm module.

The exploit required the convergence of at least three distinct bugs.

The main flaw, directly identified by KiiChain, was an underflow in the staking precompile’s process for updating balances after delegation. Cosmos Labs subsequently confirmed this bug contributed to the attacks on MANTRA and TAC as well.

KiiChain withheld details about the other two contributing issues. The report stated: "Due to security reasons, we cannot disclose the real issue at this time," leaving much of the root-cause analysis incomplete.

Cosmos Labs’ postmortem later clarified the situation by describing two interconnected balance-accounting bugs: specifically, a vesting-account underflow and a victim-balance overflow that enabled the attacker to divert actual tokens without minting new coins.

Standard wallets could not trigger this exploit. Regular accounts are unable to delegate beyond their spendable balance, so the underflow is inaccessible without further manipulation.

The attacker devised a workaround: by calculating in advance the address where a contract would be deployed, then converting this address into a vesting account before the contract’s deployment, and finally deploying the contract onto this address.

Upon deployment, the contract would inherit the vesting status, and by delegating one wei more than the available balance, its EVM balance would underflow to approximately 2^256.

With this setup, the attacker leveraged the remaining vulnerabilities, as later confirmed by Cosmos Labs, to move real tokens from victims’ accounts to their own.

No extra tokens were minted; each theft was limited to the victim’s existing balance.

KiiChain’s report does not clarify why this tactic could be used successfully 18 times against different targets in a single day without being detected after the first incident.

If MANTRA’s exploit used a hardcoded target and TAC’s left the victim as a variable, what structural decision allowed the KiiChain attacker to execute the attack so many more times?

A Split Outcome

KiiChain confirmed that 148,326,583.15 KII were stolen across 18 attacks on August 22, 2026.

Block production halted at 9,355,723, leaving 80,728,575.06 KII, or 54.4% of the total loss, in addresses controlled by the attacker but still on KiiChain. The project planned to transfer these to recovery wallets during the restart.

The remaining 67,597,997.87 KII was bridged to BNB Chain using Hyperlane; of this, 64,597,997.87 KII was sold via DEXs and 3 million KII was sent to a KuCoin deposit.

Two reconstructed attack sequences reveal a repeatable process, not just a single transaction.

In each example, the attacker created and funded a delayed-vesting account with 2 KII.

KiiChain reported that these addresses were precomputed for subsequent EVM contract deployment.

Next, the attacker deployed a helper contract at the precomputed address.

A following EVM call delegated 2 KII plus one wei—just beyond the available balance—and debited a targeted victim wallet; this caused the helper’s EVM balance to underflow, according to KiiChain.

In the first reconstructed sequence, a later helper call transferred the drained funds from the temporary helper/vesting address to the attacker’s main wallet.

This process was repeated against 18 different victims.

Sums referenced in this case file

The attacker's first visible transactions on KiiChain show a pattern of setup, contract deployment, victim drain, and sweeping funds—all within about four minutes.

A reconstructed later sequence follows the same pattern, transferring over 42 million KII from another victim to a new helper address.

While these samples do not capture all 18 incidents, they illustrate the method used throughout the event.

First Reconstructed Sequence:

At 20:32:15 UTC, the attacker set up a delayed-vesting address and funded it with 2 KII.

Vesting-Account Setup (2 KII): 4A86F67CFC909E29C640BC52E0BE7DF663F0E01C99B0D4150A9853922A356D54

Seventy-eight seconds later, an EVM contract-creation transaction established the helper contract.

Helper-Contract Deployment: D9A2445151C89CA0B49C069D509A51C8A968EB82F6377531E904B23BC94609AD

At 20:35:54 UTC, the attacker interacted with this helper contract, delegating 2,000,000,000,000,000,001 akii (2 KII plus one wei), though only 2 KII had been funded.

This transaction debited 1,023.953 KII from a victim and credited it to the helper address.

Victim Drain (1,023.953 KII): D89E47F892962A6366D8F151BC7E3DD9687982FF858EA48D939C3F8217FA1DCA

Forty-four seconds later, another EVM call moved 1,025.953 KII from the temporary helper to the attacker's main wallet.

Helper-to-Attacker Sweep (~1,025.953 KII): 12516318DACF80A376A1E5CB662D27EC32060882813C816DDCBC862464C5FDAE

Key Addresses:

Later Sequence:

At 22:32:44 UTC, the attacker repeated the setup, again funding a delayed-vesting address with 2 KII.

Vesting-Account Setup (2 KII): 85081A4BFE2A7329C9ED4772AD2F9AD765663986B23598D77A87F7E85FA08504

At 22:34:02 UTC, a new helper contract was deployed.

Helper-Contract Deployment: 3074A3C7E22CFD4A60A16500898E763A0EFA62BF582304C23024006DF0EC4476

At 22:36:21 UTC, another EVM call delegated 2 KII plus one wei, draining 42,178,466.002176081424538812 KII from a new victim to the helper address.

Helper Contract: 0x8F37701914d60CeE95CcAa39AF959561045CF9E8

Victim Drain (42,178,466.002176081424538812 KII): 4FC1440E411EEF245BB6111E7D72F89F4883FE4022C7D7B0E60A36D2A1E3DB84

Temporary Vesting/Helper Address: Kii13umhqxg56cxwa9wv4gu6l9v4vyz9e70g4hupvn

Victim Address: Kii1fsr2zu92l4gexcz9fdgatucddlduahy250pygy

The same attacker address on BSC liquidated KII through PancakeSwap.

Significant Infrastructure:

KiiChain’s recovery list mentioned two attacker wallets and three helper contracts, but not the early helper contract observed above.

The initial reconstructed sequence shows this contract received stolen funds and forwarded them to the main attacker wallet. However, the public recovery plan does not specify if this contract is covered by the planned measures.

No clarification was provided as to whether it is included via an unlisted address, a broader migration, or another method.

While the transaction trail shows how funds moved, KiiChain’s communications describe how the situation was managed.

What information was made available to others while the attack played out on-chain?

Market and Recovery Timeline

KII had only been publicly traded for eight days at the time of the attack.

The token debuted on August 14 and reached a peak of $0.0977 that day. Following the halt, KII fell by 83%.

By August 25, the price was $0.0595, down 21% for the week, with a market capitalization of about $19.3 million.

Timing was crucial: KiiChain, barely a week into trading, was the third network in as many days to be disabled by this flaw, following MANTRA on August 20 and TAC earlier on August 22.

Cosmos Labs made its first public reference to an "ongoing security incident" on August 24, after private alerts had already been sent to Cosmos EVM chains.

Publicly, Cosmos Labs advised all chains running vulnerable versions to halt on August 25—six days after the affected release was published.

The comprehensive postmortem was released August 28, stating that six networks in total had been exploited.

The postmortem reported that attackers’ centralized exchange accounts had been frozen pending further investigation.

KiiChain restarted block production on August 28 and announced that the network was fully functional again. The team declared the recovery a success, claiming most tokens were restored and explicitly stating that no user funds were lost.

However, 67,597,997.87 KII—representing 45.6% of the total stolen—had already been bridged away, and about 95.6% of that was liquidated or exchanged before the public statement.

If nearly half the stolen tokens were irretrievably moved before KiiChain declared users whole, what did "no user funds lost" actually mean, and who bore the cost?

Eighteen incidents. KiiChain identified only one bug themselves; the remaining details were left to Cosmos Labs.

On August 22, 148,326,583.15 KII were drained from KiiChain, valued at about $9.7 million at the time. The portion swapped on BSC netted approximately $1.6 million for the attacker.

The gulf between these figures illustrates what can and cannot be achieved through a chain halt.

54.4% of the tokens were frozen on-chain. The rest had already been bridged out before KiiChain’s documentation was complete, rendering them unrecoverable by the halt.

The exploited bug was found in shared Cosmos EVM code—the same issue that struck MANTRA and TAC that week. None of it originated in KiiChain’s custom code.

KiiChain alleges Cosmos Labs was aware of the vulnerability months prior, categorized it as low-risk, and released a fix without privately warning dependent chains.

Cosmos Labs’ first public acknowledgment came two days after both KiiChain and TAC were compromised.

While a chain halt can be executed within minutes, a vulnerability known for months can become an ecosystem-wide crisis in a matter of days.

KiiChain acted more quickly than the other affected chains, provided more technical detail, and still saw tens of millions in tokens lost beyond the reach of mitigation tools like blocklists.

A network can be faster and more transparent than its peers, pause operations quickly enough to salvage a majority of tokens, and still declare victory even as large portions of the incident’s root cause remain undisclosed.

If neither rapid response nor open reporting was enough to prevent nearly half of the stolen funds from being lost, what must change at the protocol level to avoid similar incidents in the future?

CosmosKiichain
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.