An attack on the Cosmos EVM ecosystem turned into a resounding fiasco for the attacker. He managed to find a critical vulnerability and mint Nesa (NES) tokens worth about $50 million, but the actual profit amounted to a paltry $60,000. The market punished the hacker itself.
I managed to trace the entire chain of transactions using analytical tools, and the picture turned out to be extremely instructive. The attacker acted cautiously: he funneled $250,000 into the main wallet 0x9AE7 via Monero (XMR) to cover his tracks. Then, using a bug in Cosmos EVM, he increased the balance 200-fold and sent about $50 million in NES back to the Ethereum network.
Then the classic laundering scheme began: the tokens passed through eight intermediate addresses, where they were swapped for ETH on decentralized exchanges, and then the funds were withdrawn to centralized platforms. But here the hacker faced an unpleasant surprise.
Why the attack failed
The liquidity in the pools turned out to be so limited that it ran out before the attacker managed to sell the bulk of the tokens. The massive dump of NES caused catastrophic price slippage, which literally destroyed the value of the stolen assets. As a result, with costs of $255,000, the hacker managed to net only $315,000 — a meager profit by the standards of such crimes.
Cosmos Labs has already responded to the incident, recommending that all networks using vulnerable versions of the module (below v0.6.2 or v0.7.2) immediately halt block validation and install updates. The team confirmed that many affected chains have already fixed the issue, but promised to provide a detailed report on the scale of the damage later.
The attack affected at least four networks on the shared module: KiiChain, where the hacker repeated the exploit 18 times and withdrew over 148 million KII, Nesa, MANTRA, and TAC. In Nesa, developers noticed the intrusion attempt at the Layer 1 level and temporarily suspended the service until a patch was installed.
My analysis: This case is a vivid illustration that even successful exploitation of a vulnerability does not guarantee wealth for the hacker. The market, with its low liquidity and slippage, acts as a natural defense mechanism that can neutralize the consequences of technical breaches. However, the incident highlights a systemic problem: modular blockchain ecosystems such as Cosmos remain vulnerable due to a single point of failure in shared code. Projects based on Cosmos EVM should reconsider their security protocols before more sophisticated attacks emerge.