Key Takeaways:
- Attacker inflated NES balance 200x via Cosmos EVM bug
- $50M bridged to Ethereum, but vanishing liquidity capped profit
- Cosmos Labs urged chains on vulnerable versions to halt and patch
Key Takeaways:

An attacker exploited a Cosmos EVM bug to move $50 million of Nesa (NES) off-chain, netting just $60,000.
Blockchain analytics firm Bubblemaps traced the exploit to wallet 0x9AE7, which bought $250,000 of NES and bridged the tokens to Nesa Chain before inflating the balance 200 times through the vulnerability.
The attacker then bridged roughly $50 million of NES back to Ethereum, routing the tokens through eight addresses that swapped NES for ETH on decentralized exchanges before depositing proceeds to centralized platforms. Liquidity disappeared from pools before most of the selling completed, and extreme slippage reduced the haul to $315,000 against $255,000 spent — a net profit of about $60,000.
Cosmos Labs disclosed the incident Aug. 24 and advised chains running Cosmos EVM versions below v0.6.2 or v0.7.2 to halt validators and upgrade. At least four networks running the shared module reported problems: Nesa, KiiChain, MANTRA, and TAC.
The main wallet was funded through Monero (XMR), with roughly $45,000 and $211,000 in separate transfers routed through privacy tools before reaching addresses connected to the exploit, according to Bubblemaps. One recorded transaction on Etherscan shows the liquidity problem clearly: an aggregated swap attempting to sell 5,000,000 NES worth about $710,000 returned only about $1,928 worth of ETH.
NES fell as much as 90 percent in the immediate aftermath before recovering considerably in the hours that followed. Investigators believe the recovery was driven largely by arbitrage activity between mismatched prices on decentralized exchanges and centralized exchanges after the attack. NES trades at $0.133, down 6.9 percent over 24 hours, with a circulating supply of about 141.5 million tokens against a total supply of 1 billion.
KiiChain said an attacker repeated the same technique 18 times, draining 148,326,583.15 KII. Nesa notified users it had identified malicious activity exploiting the Cosmos EVM vulnerability on its layer-1 and said services would resume after a software fix. MANTRA and TAC also confirmed impact, though neither has disclosed specific loss figures.
Cosmos Labs has not yet named the vulnerability, the affected chains, or the total loss figure. The team has promised an incident report once the response ends. Whether other chains running the module took quieter losses will not be clear until that report is published.
The exploit highlights a structural risk in the Cosmos ecosystem, where multiple chains share the same EVM module. A single vulnerability can cascade across networks, and the gap between the headline $50 million figure and the $60,000 realized profit shows how quickly liquidity can evaporate once an exploit is detected.
This article is for informational purposes only and does not constitute investment advice.