An attacker recently exploited a vulnerability in the Cosmos EVM to move $50 million worth of Nesa (NES) tokens off the project’s chain. However, due to market mechanics, the final payout was reduced to approximately $60,000.
Blockchain analytics firm Bubblemaps traced the wallets involved in the incident. According to Bubblemaps, the primary wallet, designated as 0x9AE7, initially purchased $250,000 of NES and bridged the tokens to Nesa Chain after being funded through Monero (XMR).
How the Exploit Unraveled
The attacker used the exploit to inflate their token balance by 200 times. Approximately $50 million of NES was then bridged back to Ethereum (ETH).
The tokens were subsequently routed through eight addresses, where they were swapped for ETH on decentralized exchanges before the proceeds were sent to centralized platforms. Bubblemaps noted that liquidity vanished from the pools before the selling process finished. As a result, the swaps encountered extreme slippage that consumed nearly the entire position, leaving the attacker with a recovery of $315,000 against $255,000 spent.
Cosmos Labs Response and Impacted Networks
Cosmos Labs disclosed the security incident on August 24 and advised affected chains to have validators halt operations. The team recommended that any chains utilizing a Cosmos EVM version earlier than v0.6.2 or v0.7.2 immediately halt their blockchains and upgrade to include the necessary patches.
Cosmos Labs has not yet named the specific vulnerability, disclosed total loss figures across the ecosystem, or identified all affected chains, but it promised to release an incident report once the response concludes.
Four networks running the shared module have reported issues stemming from the vulnerability:
- Nesa: Notified users of malicious activity on its layer-1 and stated services will return online following a software fix.
- KiiChain: Reported that an attacker repeated the same technique 18 times, draining 148,326,583.15 KII tokens.
- MANTRA and TAC: Also identified as impacted networks.
The full extent of the losses across other chains running the vulnerable module remains unclear pending the release of the official incident report from Cosmos Labs.


