An exploit in the Cosmos EVM module allowed an attacker to mint Nesa (NES) tokens worth approximately $50 million. However, due to catastrophic slippage and illiquid pools, the hacker managed to convert only a small portion into real funds — roughly $60,000 in net profit.

My analysis of the transaction chain shows that the attack was carefully planned. The attacker, operating through the anonymous wallet 0x9AE7, purchased NES for $250,000, having previously laundered funds through Monero (XMR) to conceal their tracks. Then, using a critical vulnerability in Cosmos EVM, they increased their balance 200-fold, creating tokens worth $50 million.

How the attack on Nesa unfolded

The generated tokens were transferred back to the Ethereum network and distributed across eight addresses. From each of them, NES was gradually exchanged for ETH through decentralized exchanges, with the proceeds directed to centralized platforms for further liquidation.

However, the plan hit a snag: liquidity in the pools dried up faster than the hacker could sell the bulk of the tokens. The slippage proved so devastating that almost nothing remained of the nominal amount. In the end, the attacker netted only $315,000 against costs of $255,000 — a laughable profit compared to the potential $50 million.

Cosmos Labs advises stopping networks

Cosmos Labs confirmed the incident and recommended that all related networks immediately halt block validation. According to the official statement, many affected chains have already fixed the issue. For networks using Cosmos EVM versions below v0.6.2 or v0.7.2, it is strongly recommended to stop the network and install patches.

At this point, the team has not disclosed the nature of the vulnerability itself, has not named the full list of affected networks, and has not assessed the overall damage. However, it is known that at least four networks running on the shared module were attacked: KiiChain, Nesa, MANTRA, and TAC. On KiiChain, the attacker repeated the attack 18 times, withdrawing 148,326,583.15 KII.

Nesa developers also recorded an attempted hack through the same breach in their L1 network and will restore service only after installing the update. The full picture of the incident will become clear only after Cosmos Labs publishes a detailed report.

My expert opinion: this case is a vivid illustration that the nominal value of stolen assets often does not reflect the hacker's real gain. However, far more alarming is that such a fundamental vulnerability in the base module affected several networks at once. This calls into question the overall security of the Cosmos ecosystem and requires an immediate review of audit practices and codebase updates.