In August 2026, two incidents pointing to "foundations" brought the foundational security of public chains into the spotlight: on one side, the EVM module widely reused in the Cosmos ecosystem encountered a multi-chain attack between August 20 and 25, with at least 6 networks/chains affected according to a single source. MANTRA was the first to alert the Cosmos security team, and Cosmos Labs promptly released an incident analysis and collaborated with about 40 chains using related modules to assess risks and deploy mitigation measures; on the other side, Polygon disclosed serious vulnerabilities in the core Bor block producer client and Heimdall validation layer of its PoS network, and according to a single source, such defects could evolve into denial-of-service or resource exhaustion issues. Ultimately, Polygon completed repairs through two hard forks codenamed Austin and Kyoto by the end of August. The two alerts that rang continuously within the month exposed the risk concentration effects of modular reuse and dual-client architecture on public chain infrastructure, and also tested under real pressure whether the emergency responses, cross-team collaboration, and public disclosure mechanisms of Cosmos and Polygon could withstand systemic shocks.
EVM Module Breached: Cosmos Multi-Chain Chain Reaction
While Polygon was busy patching its dual clients, Cosmos was facing a more typical "module reuse incident" at the other end. The Cosmos ecosystem is known for its modularity, with the EVM module serving as a core component compatible with Ethereum, directly embedded in the application scenarios of multiple chains. According to a single source, within just a few days from August 20 to 25, at least 6 networks or chains using this module were attacked one after another, with the timing window highly overlapping, pointing towards the same underlying vulnerability rather than isolated single-chain incidents.
More troubling is that the list of victim chains, the identity of attackers, and specific exploitation methods in this chain-reaction incident have not been confirmed in existing public materials; what the outside world can see is merely the simultaneous rips of the same EVM module across multiple chains. Modularity was supposed to save developers time and reduce the cost of reinventing the wheel, but when a compatible layer utilized by the entire ecosystem exposes vulnerabilities, the single point defect is immediately magnified into systemic risk. According to a single source, Cosmos Labs subsequently published a security incident analysis report regarding the EVM module, providing a basis for repair and review, while starkly laying bare the ecosystem's high reliance on this compatible module in the agenda for future security strengthening.
From Warning to Blocking: A Record of Cosmos Ecosystem Self-Rescue
When attacks began to emerge on multiple chains, according to a single source, the first to press the "alarm button" was MANTRA. After discovering anomalies on its own, it promptly reported issues suspected to be related to the EVM module to the Cosmos security team, gaining valuable rounds for the entire ecosystem to respond from chaos. At this point, the problem was no longer merely self-preservation of a single chain, but how to prevent the fire from spreading in a highly modular network that shared the same compatible layer.
According to a single source, Cosmos Labs and the security team immediately initiated a joint investigation across approximately 40 chains: which links incorporated the at-risk EVM module, their respective operational versions and configurations, and whether abnormal transactions or state changes had occurred, were all included in the same risk control list. Existing materials did not disclose patch details or timelines for each chain's upgrades, but it can be confirmed that this round of response focused on module upgrades, parameter adjustments, and information synchronization. This forced the originally loose multi-chain system to accelerate alignment in audit processes, upgrade rhythms, and communication mechanisms, while also revealing to everyone that when cross-chain synchronous decision-making is truly needed, the efficiency of multi-party collaboration still has an undeniable real limit.
Polygon Dual Client Exposes Vulnerability: Two Hard Forks
Unlike Cosmos coordinating module upgrades across multiple chains, Polygon exposed core infrastructure issues within a single PoS network this time. Its PoS network relies on Bor as the block producer client and Heimdall as the validator layer client. If these two layers encounter problems, it directly affects the heart of consensus. According to a single source, Polygon disclosed in August 2026 that its PoS network had serious vulnerabilities at these two client layers, which could be exploited to create denial-of-service or resource exhaustion risks; however, existing public materials did not indicate the specific affected module locations or attack paths, nor whether they had been actively exploited prior to disclosure.
In the face of such foundational hazards, Polygon chose to execute two consecutive hard forks codenamed Austin and Kyoto on its mainnet, completing repairs through consensus upgrades. According to a single source, both upgrades were implemented before August 30, 2026, meaning the repairs were completed by the validators collectively as an urgent route while maintaining ongoing block production and validation on the chain. Compared to Cosmos, which needed to synchronize patches and risk awareness across dozens of chains, Polygon compressed decision-making and execution cycles within a single network through two phases of hard forks, providing a reviewable emergency path for how to balance continuous network operation with rapid repairs in the face of security issues exposed at the dual client layer of the PoS public chain.
Sequential Alarms in the Same Month: Common Risks in Public Chain Foundations
In August 2026, the Cosmos EVM module and Polygon PoS client sequentially raised alarms, shifting the risk focus from a single DApp or cross-chain bridge to the levels of "shared modules" and "PoS clients." The former is an Ethereum-compatible component reused by dozens of chains in the Cosmos ecosystem, with a single vulnerability triggering a chain reaction of attacks on at least 6 chains between August 20-25; the latter supports Bor and Heimdall dual clients for Polygon PoS block production and validation, with any code defect inherently carrying systemic risks at the network level. The design of module reuse and client sharing was originally an engineering choice to enhance development efficiency and ecosystem compatibility, yet within this window, it synchronously exposed that as long as one link in the foundation goes wrong, the impact will far exceed a single application.
According to a single source, under the leadership of the security team on the Cosmos side, about 40 chains using related EVM modules assessed risks and deployed mitigation measures; Polygon, meanwhile, internally completed fortification against the Bor and Heimdall vulnerabilities through two hard forks codenamed Austin and Kyoto before August 30. Existing public materials did not show any direct technical connection or common attackers between the two incidents, but rather reflected a resonance-like concentration exposure of risk types around "core software components" in the same month. Compared to previous practices where project parties tended to conduct closed investigations and downplay incidents afterwards, this round of synchronized disclosure and cross-team collaborative repairs indicates that the security issues of foundational facilities are being more publicly placed on the table, also forcing the industry to reevaluate those widely reused foundational modules and client implementations that have long been considered inherently reliable.
From Incidents to Normalcy: Security Games Continue
Bringing the timeline back to August 2026, the two incidents completed the "discovery—disclosure—repair" closed loop within a limited window: on the Cosmos side, through EVM module repairs and collaboration with about 40 chains, and on the Polygon side through the consecutive execution of the Austin and Kyoto hard forks on the Bor and Heimdall dual clients. According to public information, both managed to avoid irretrievable chain-level paralysis but also exposed gaps in preventive mechanisms and automated defenses. Current materials have not provided explicit economic loss figures or confirmed the identities of the attackers, making the role division of the security team, project parties, and community in the event a more critical sample for assessing future governance maturity. What is worth observing going forward is whether audits of modules and clients can form a high-frequency norm, whether cross-project intelligence sharing can alert in advance before the next anomaly triggers, and whether each ecosystem will weigh "quick reparability" and "multi-party coordination costs" alongside performance and scalability when designing new chains.
Join our community, let’s discuss together and become stronger!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



