The attack on the Cosmos EVM ecosystem turned out to be a spectacular failure for the hacker. He managed to cause tens of millions of dollars in damage, but his actual profit was only $60,000. Let's break down the details of the incident that exposed critical vulnerabilities in the blockchain module.
My analysis of the transaction chain shows that the attacker acted thoughtfully but faced the harsh reality of the market. Using a vulnerability in Cosmos EVM, he issued Nesa (NES) tokens worth about $50 million. However, as it turned out, liquidity in the pools was so limited that most of the stolen assets simply could not be monetized.
Attack Mechanics: From Monero to Balance Multiplication
The starting point was wallet 0x9AE7, which received $250,000 via the anonymous cryptocurrency Monero (XMR). These funds were used to buy NES and then transfer them to the Nesa Chain network. Next, the hacker applied an exploit, increasing his balance 200-fold. As a result, about $50 million in NES were sent back to the Ethereum (ETH) network.
The subsequent scheme looked like this: the tokens passed through eight intermediary addresses, from each of which NES were exchanged for ETH on decentralized exchanges. The resulting funds were then withdrawn to centralized platforms. But this is where the key mistake emerged—slippage turned out to be catastrophic. Liquidity dried up faster than the hacker could sell the entire volume. The result: with costs of $255,000, the attacker received only $315,000, making the entire operation almost pointless from a financial perspective.
Cosmos Labs' Response and the Scale of the Threat
Cosmos Labs responded promptly to the incident, recommending that all related networks immediately halt block validation. The official statement emphasizes: "Many affected chains have already fixed the issue. We continue to provide information on mitigating the vulnerability. For chains using Cosmos EVM versions below v0.6.2 or v0.7.2, it is recommended to immediately stop the network and update it with the patches from these releases."
So far, four affected networks running on the shared module are known. In KiiChain, the hacker repeated the attack 18 times, withdrawing 148,326,583.15 KII. Nesa developers also confirmed an attempted breach through the same vulnerability in their Layer 1 network. The service will be restored only after the update is installed. Projects such as MANTRA and TAC were also hit.
Cosmos Labs has not yet disclosed the details of the vulnerability itself, has not named the full list of affected networks, and has not assessed the total damage. A detailed report is promised after the consequences are resolved.
My comment: This case is a vivid example that a technical vulnerability is only half the problem. The other half is liquidity and market pressure. The hacker underestimated that even millions of tokens are worth nothing without market depth. For the industry, this is a wake-up call: code security in multi-chain ecosystems must be a priority, but projects themselves should also think about how quickly their assets can depreciate in a force majeure. The incident also highlights the importance of Monero's anonymity—this tool remains a favorite among attackers, complicating fund tracking.