A recent incident in the Cosmos ecosystem exposed a serious vulnerability in the Cosmos EVM module, but instead of the expected "jackpot," the attacker faced the harsh reality of the market. The attack on the Nesa protocol (NES) showed that even a successful exploit can yield only symbolic profit if liquidity is not taken into account.
How the Attack on Nesa Unfolded
My analysis of the transaction chain shows that the attacker acted deliberately. The initial capital of $250,000 was acquired through Monero (XMR)—an anonymous cryptocurrency traditionally chosen by those who value privacy above all else. These funds were transferred to the wallet 0x9AE7, after which the hacker used a critical bug to increase his balance 200-fold.
As a result, he managed to generate NES tokens worth approximately $50 million and transfer them to the Ethereum network. However, subsequent actions revealed his miscalculation: the tokens were distributed across eight addresses, from which he attempted to exchange them for ETH via decentralized exchanges. But the liquidity in the pools turned out to be so limited that slippage wiped out virtually the entire amount.
The outcome was dismal for the hacker: with costs of $255,000, he managed to net only $315,000. The net profit amounted to a paltry $60,000—less than 0.2% of the nominal value of the stolen tokens.
Cosmos Labs' Response and the Scale of the Problem
Cosmos Labs responded promptly to the incident, recommending that all networks using vulnerable versions of Cosmos EVM (below v0.6.2 or v0.7.2) immediately halt block validation. The team confirmed that many affected chains have already fixed the issue, but a detailed report on the nature of the vulnerability and the full damage will be published later.
It is known that the attack affected at least four networks running on the shared module. In KiiChain, the attacker repeated the exploit 18 times, withdrawing over 148 million KII tokens. Nesa, MANTRA, and TAC were also affected. Nesa developers have already confirmed an attempted hack through the same vulnerability and suspended service operations until updates are installed.
My verdict: This case is a stark reminder that in the world of DeFi, the nominal value of an asset and real liquidity are two very different things. Hackers often underestimate this factor, and here the market itself acted as the defender. However, the incident underscores the critical importance of security audits for all networks based on Cosmos EVM—until the vulnerability is fully disclosed, other chains remain at risk.