Skip to main content
AVOID.NET
KiiChain1 decision on this page

Audit log

Every state-changing event for KiiChain: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-11 23:00:45Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,276,654
    sig
    3LKhiwDuP4AZ…B2ENUEi1explorer ↗
    hash
    2za1YgehuCLL…cpdAdK5Nsha256 → base58
    verifying row…full verify ↗
    canonical bytes (18065 B) ▸
    {"actor":"system:backfill","investigation_id":"eb0bb2dc-b473-44bd-9669-2400b72f1a9d","kind":"publish","page_slug":"kiichain","published_at":"2026-09-11T23:00:44.981Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"KiiChain","sections":[{"content":"On August 22, 2026, an attacker drained 148,326,583.15 KII from KiiChain across 18 repeated attack sequences targeting different accounts, using an identical technique each time. According to KiiChain's own incident report and reporting by Rekt News, the exploit required three coordinated defects in the shared Cosmos EVM module: an underflow in the staking precompile's post-delegation balance write-back, plus two additional undisclosed vulnerabilities affecting vesting-account and victim-balance handling. The attacker's method involved pre-computing the future deployment address of a helper smart contract, funding that address with exactly 2 KII and registering it as a delayed-vesting account before the contract existed, then deploying the contract so it inherited vesting status. The contract then delegated slightly more than its funded balance (2 KII plus one wei), triggering an integer underflow that inflated its mirrored EVM-side balance to approximately 2^256, after which real tokens could be redirected from the inflated balance to the attacker's wallet. Cosmos Labs described the underlying defect as a staking-precompile underflow occurring during the balance write-back to the EVM side after a delegation.","heading":"The Exploit","severity":"critical","sources":[{"credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks","type":"news_article","url":"https://thedefiant.io/news/blockchains/cosmos-labs-urges-evm-chains-halt-shared-bug-drains-three-networks"},{"credibility":2,"name":"Cosmos Labs Urges EVM Chains to Halt as KiiChain and TAC Attacks Raise Security Fears","type":"news_article","url":"https://cryptopotato.com/cosmos-labs-urges-evm-chains-to-halt-as-kiichain-and-tac-attacks-raise-security-fears/"}]},{"content":"The nominal value of the 148,326,583.15 KII drained was approximately $9.7 million at pre-exploit prices, though Rekt News estimated actual realized proceeds to the attacker at roughly $1.6 million once liquidation slippage and price impact are accounted for. Of the total, 80,728,575.06 KII (about 54.4%) never left KiiChain and remained in attacker-controlled accounts when the chain halted, giving investigators an on-chain snapshot and a path to potential recovery via blocklisting. The remaining 67,597,997.87 KII was bridged to BNB Chain via the Hyperlane cross-chain messaging protocol; of that, 64,597,997.87 KII was swapped for BUSD/USDT on BNB Chain decentralized exchanges (reported as PancakeSwap), and 3,000,000 KII was sent to a KuCoin deposit address that was subsequently frozen pending investigation. Because bridging and liquidation occurred before KiiChain finished halting the network and drafting its incident report, most of the bridged-and-sold portion is considered difficult to recover.","heading":"Scale of Losses and Fund Movement","severity":"high","sources":[{"credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"KiiChain Halts Network After EVM Exploit Moves Funds Through Hyperlane to BSC","type":"news_article","url":"https://cryptoadventure.com/kiichain-halts-network-after-evm-exploit-moves-funds-through-hyperlane-to-bsc/"},{"credibility":2,"name":"Cosmos Labs Bug Drains Six Chains, $5.7M","type":"news_article","url":"https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/"}]},{"content":"The defect exploited on KiiChain was not application-specific to KiiChain but resided in the shared cosmos/evm module used by numerous Cosmos SDK chains that run EVM-compatible smart contracts. The same class of vulnerability was used to attack MANTRA Chain (approximately 720.9 million tokens, roughly $3.6 million) on August 20, 2026, and the TAC Protocol bridge (approximately 2.98 billion TAC, reported as around 62% of circulating supply) on August 22, 2026. Reporting by crypto.news indicated at least six chains were affected in total, with combined losses across all incidents estimated around $5.7 million in realized proceeds; a chain called Nesa was also named as affected, with roughly $60,000 in net attacker profit despite converting around $50 million in NES tokens. Cosmos Labs stated it coordinated privately with 40 networks and said it helped 13 chains patch or halt before they could be attacked. AVOID.NET's corpus separately covers MANTRA Chain and the TAC Protocol bridge as related incidents stemming from this same shared defect.","heading":"Shared Vulnerability Affecting Multiple Cosmos EVM Chains","severity":"high","sources":[{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"credibility":1,"name":"Cosmos Labs Confirms Cosmos EVM Incident as 3 Chains Disclose Impact","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/cosmos-labs-confirms-cosmos-evm-043443408.html"}]},{"content":"According to Rekt News and KiiChain's own public post-mortem, Cosmos Labs had allegedly known of the underlying flaw for months before it was exploited, with one of the three defects reportedly first reported through Cosmos Labs' bug bounty program around April 25, 2026 — nearly four months before the attacks. Cosmos Labs published a public fix for one of the three defects on August 19, 2026, without an accompanying security advisory or explicit warning that the change was security-critical; the patched release (cosmos/evm v0.7.2) was described by KiiChain as bundled with unrelated changes. The first attack in the broader campaign (against MANTRA) reportedly began roughly 20 hours after the patch went public, a timing pattern that KiiChain and other affected chains have alleged is consistent with attackers reverse-engineering the vulnerability from the public code diff, though this causal link has not been independently proven and should be treated as an allegation. Cosmos Labs did not publicly acknowledge an \"ongoing security incident\" until August 24, 2026, and did not issue a public recommendation that affected chains halt until August 25, 2026 — after KiiChain, MANTRA, and TAC had already been drained. KiiChain publicly criticized this response, stating in its post-mortem that \"a patch takes days to review, build, test and roll out across a validator set. A halt takes minutes,\" and argued the halt recommendation reached it only after damage was already done. Cosmos Labs, for its part, has stated that a 20-hour window was not realistic for coordinating a state-breaking upgrade across independent validator sets. As of early September 2026, KiiChain stated that two of the three defects it identified remained unpatched, and other chains (e.g., XRPL EVM sidechain) were reported to still be running a vulnerable module version.","heading":"Disclosure and Patch-Timing Controversy","severity":"critical","sources":[{"credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"Cosmos Labs Bug Drains Six Chains, $5.7M","type":"news_article","url":"https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/"},{"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"}]},{"content":"KiiChain halted block production on August 22, 2026 at block 9,355,723 (reported at approximately 22:50:58 UTC) after internal detection of the drain sequences. The network resumed operations on August 28, 2026, publicly stating that no user funds were ultimately lost, a characterization that Rekt News' reporting frames as requiring context, since a substantial share of the drained tokens had already been bridged off-chain and liquidated by the time the network resumed. KiiChain's recovery plan reportedly relies on blocklisting attacker-controlled addresses holding the roughly 80.7 million KII that remained on-chain.","heading":"Network Halt and Resumption","severity":"medium","sources":[{"credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"},{"credibility":2,"name":"Cosmos requests validators to 'halt their chains' after EVM breach: 148.3M KII lost","type":"news_article","url":"https://ambcrypto.com/cosmos-requests-validators-to-halt-their-chains-after-evm-breach-148-3m-kii-lost/"}]},{"content":"KiiChain is a Cosmos SDK-based Layer 1 blockchain positioned as financial infrastructure for onchain foreign exchange (FX), cross-border payments, and stablecoin settlement, built by Kii Global. Kii Global's ecosystem also includes KIIEX, described as a hybrid exchange and payment platform. According to Kii Global's own documentation, the organization began as an over-the-counter FX operation before expanding into blockchain infrastructure; KiiGlobal S.A.S. is organized in Colombia as a subsidiary of EMF Group SA de CV in El Salvador, with a stated focus on emerging-market and Latin American settlement and liquidity. Publicly identified leadership includes co-founder and CEO Danyel Arenas, co-founder and COO Alex Cavallero, with Jhelison Uchoa cited as leading technology. The KII token reportedly launched around August 14, 2026, only about a week before the exploit, reaching an all-time high near $0.0977 shortly before the attack.","heading":"About KiiChain / Kii Global","severity":"low","sources":[{"credibility":2,"name":"KiiChain | Kii Docs","type":"official","url":"https://docs.kiiglobal.io/docs/learn/kiichain"},{"credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"}]}],"sources_used":[{"archive_timestamp":"2026-09-11T21:52:46+00:00","archive_url":"https://web.archive.org/web/20260911215246/https://rekt.news/kiichain-rekt","credibility":2,"name":"Kiichain - Rekt News","type":"research","url":"https://rekt.news/kiichain-rekt"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"Cosmos EVM vulnerability drains MANTRA, TAC and KiiChain in cross chain attacks","type":"news_article","url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"Cosmos Labs Urges EVM Chains to Halt as KiiChain and TAC Attacks Raise Security Fears","type":"news_article","url":"https://cryptopotato.com/cosmos-labs-urges-evm-chains-to-halt-as-kiichain-and-tac-attacks-raise-security-fears/"},{"archive_timestamp":"2026-09-01T06:13:35+00:00","archive_url":"http://web.archive.org/web/20260901061335/https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/","credibility":2,"name":"Cosmos Labs Bug Drains Six Chains, $5.7M","type":"news_article","url":"https://coinpaprika.com/news/cosmos-labs-bug-drains-six-chains-57m/"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"KiiChain Halts Network After EVM Exploit Moves Funds Through Hyperlane to BSC","type":"news_article","url":"https://cryptoadventure.com/kiichain-halts-network-after-evm-exploit-moves-funds-through-hyperlane-to-bsc/"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"Cosmos Labs Urges EVM Chain Halts After KiiChain 148M KII Exploit","type":"news_article","url":"https://cryptoadventure.com/cosmos-labs-urges-evm-chain-halts-after-kiichain-148m-kii-exploit/"},{"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null,"archive_url":null,"credibility":2,"name":"Cosmos Labs Urges EVM Chains To Halt As Shared Bug Drains Three Networks","type":"news_article","url":"https://thedefiant.io/news/blockchains/cosmos-labs-urges-evm-chains-halt-shared-bug-drains-three-networks"},{"archive_timestamp":"2026-08-27T22:20:32+00:00","archive_url":"http://web.archive.org/web/20260827222032/https://finance.yahoo.com/markets/crypto/articles/cosmos-labs-confirms-cosmos-evm-043443408.html","credibility":1,"name":"Cosmos Labs Confirms Cosmos EVM Incident as 3 Chains Disclose Impact","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/cosmos-labs-confirms-cosmos-evm-043443408.html"},{"archive_timestamp":null,"archive_url":null,"credibility":2,"name":"Cosmos requests validators to 'halt their chains' after EVM breach: 148.3M KII lost","type":"news_article","url":"https://ambcrypto.com/cosmos-requests-validators-to-halt-their-chains-after-evm-breach-148-3m-kii-lost/"},{"archive_timestamp":"2026-08-28T17:50:24+00:00","archive_url":"http://web.archive.org/web/20260828175024/https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/","credibility":2,"name":"Cosmos EVM chains told to halt after security incident","type":"news_article","url":"https://crypto.news/cosmos-evm-chains-told-to-halt-after-security-incident/"},{"archive_timestamp":"2026-06-08T13:43:26+00:00","archive_url":"http://web.archive.org/web/20260608134326/https://docs.kiiglobal.io/docs/learn/kiichain","credibility":2,"name":"KiiChain | Kii Docs","type":"official","url":"https://docs.kiiglobal.io/docs/learn/kiichain"}],"summary":"KiiChain, a Cosmos SDK Layer 1 chain built by Kii Global for FX and cross-border payment settlement, lost 148,326,583.15 KII tokens (nominally about $9.7 million, with an estimated $1.6 million actually realized by the attacker) on August 22, 2026, after an attacker exploited a shared, three-part integer underflow vulnerability in the Cosmos EVM precompile layer across 18 sequential transactions. The same underlying Cosmos EVM defect was used to attack MANTRA Chain and the TAC Protocol in the same window, and KiiChain has publicly disputed Cosmos Labs' disclosure and coordination timeline. The network halted at block 9,355,723 and resumed six days later; roughly 54% of the drained tokens remained on-chain and were frozen, while the rest were bridged to BNB Chain via Hyperlane and largely liquidated before the chain resumed.","timeline":[{"date":"2026-04","date_original":"2026-04-25","event":"One of the three underlying Cosmos EVM defects was allegedly first reported to Cosmos Labs through its bug bounty program, months before public disclosure or exploitation, per Rekt News and crypto.news reporting.","source":"crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08","date_original":"2026-08-14","event":"KII token reportedly launched and subsequently reached an all-time high near $0.0977.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"},{"date":"2026-08-19","date_evidence":"Patch Release: August 19, 2026 (7:01 p.m. ET)","event":"Cosmos Labs publicly released a patch (cosmos/evm v0.7.2) addressing one of the three underlying defects, without an accompanying security advisory.","source":"crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08-20","date_evidence":"First Attack: August 20, 2026 (3:06 p.m. ET) - approximately 20 hours after patch","event":"First known attack in the campaign begins, targeting MANTRA Chain, roughly 20 hours after the Cosmos Labs patch was published.","source":"crypto.news","source_url":"https://crypto.news/cosmos-evm-vulnerability-drains-mantra-tac-and-kiichain-in-cross-chain-attacks/"},{"date":"2026-08","date_original":"2026-08-20","event":"MANTRA Chain halted after losing approximately 720.9 million tokens (about $3.6 million) to the same exploit technique.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"},{"date":"2026-08","date_original":"2026-08-22","event":"Attacker drains 148,326,583.15 KII from KiiChain across 18 sequential attack transactions exploiting the Cosmos EVM underflow; TAC Protocol is also attacked the same day, losing approximately 2.98 billion TAC.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"},{"date":"2026-08","date_evidence":"22:50:58 UTC: KiiChain halted at block 9,355,723","date_original":"2026-08-22","event":"KiiChain halts block production at block 9,355,723.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"},{"date":"2026-08","date_evidence":"Aug 24, 1:06 p.m. NY time: \"ongoing security incident has impacted users of the Cosmos EVM module\"","date_original":"2026-08-24","event":"Cosmos Labs issues its first public acknowledgment of an \"ongoing security incident\"; KiiChain also publishes its own incident report the same day.","source":"The Defiant","source_url":"https://thedefiant.io/news/blockchains/cosmos-labs-urges-evm-chains-halt-shared-bug-drains-three-networks"},{"date":"2026-08","date_original":"2026-08-25","event":"Cosmos Labs publicly recommends that unpatched Cosmos EVM chains halt operations, roughly six days after the vulnerable release shipped and after MANTRA, TAC, and KiiChain had already been attacked.","source":"cryptopotato.com","source_url":"https://cryptopotato.com/cosmos-labs-urges-evm-chains-to-halt-as-kiichain-and-tac-attacks-raise-security-fears/"},{"date":"2026-08","date_original":"2026-08-28","event":"KiiChain resumes block production, stating no user funds were ultimately lost, and Cosmos Labs publishes a fuller postmortem of the incident.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"},{"date":"2026-09","date_original":"2026-09-02","event":"Rekt News publishes its detailed writeup of the KiiChain exploit.","source":"Rekt News","source_url":"https://rekt.news/kiichain-rekt"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision c5ef565c-4bbe-42f6-9282-db181f086e1d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.