A notable incident has occurred in the world of blockchain security, vividly demonstrating that even a successful exploitation of a vulnerability does not always guarantee the attacker the desired loot. This concerns an attack on the Cosmos EVM ecosystem, in which the hacker managed to mint Nesa (NES) tokens worth approximately $50 million, yet their actual earnings turned out to be negligible—only $60,000.

My analysis of the transaction chain shows that the attacker acted deliberately but encountered an insurmountable obstacle—a lack of liquidity. The initial capital of $250,000 was acquired through Monero (XMR), a classic method for ensuring anonymity. After that, the hacker exploited a critical vulnerability that allowed the balance to be increased 200-fold and directed the minted NES tokens worth approximately $50 million back to the Ethereum network.

Subsequent developments proved fatal for the attacker. The tokens were distributed across eight addresses and exchanged for ETH on decentralized exchanges, but liquidity in the pools dried up significantly before the bulk of the assets could be realized. The slippage was so catastrophic that virtually nothing remained of the nominal amount. In the end, with costs of $255,000, the hacker received only $315,000, making this attack economically unviable.

Scope of the problem and Cosmos Labs' response

Cosmos Labs responded promptly to the incident, recommending that all associated networks immediately halt block validation. According to the official statement, many affected chains have already fixed the issue, but networks using Cosmos EVM versions below v0.6.2 or v0.7.2 are strongly advised to suspend operations and install patched updates.

Notably, the vulnerability affected several networks running on the shared module at once. On KiiChain, the attacker repeated the exploit 18 times, draining 148,326,583.15 KII tokens. Nesa developers also confirmed an attempted breach through the same vulnerability in their Layer 1 network, and the MANTRA and TAC projects were affected as well. Cosmos Labs has not yet disclosed details of the vulnerability itself or the full list of affected networks, promising to provide a detailed report after the consequences are mitigated.

My comment: This incident is a stark reminder that vulnerabilities in the base module can have a cascading effect across the entire ecosystem. However, the fact that the hacker failed to monetize the attack highlights the importance of liquidity as a natural barrier. In the long term, Cosmos Labs needs to accelerate the audit and update implementation process to prevent similar incidents in the future.