The exploit in Cosmos EVM turned out to be a disappointment for the attacker: instead of a potential $50 million, he managed to extract only about $60,000 in net profit.
I managed to reconstruct the full picture of this telling attack. The attacker discovered a critical vulnerability in the Cosmos EVM module and used it to mint Nesa (NES) tokens worth over $50 million. However, the actual gain turned out to be incomparably small—just $60,000, making this incident more of a curiosity than a financial catastrophe.
Attack Mechanics: How It Happened
Based on the tracked transactions, the hacker started by purchasing NES for $250,000 through an anonymous wallet funded via Monero (XMR). Then, using the bug, he increased his balance 200-fold, creating about $50 million in NES, and transferred the tokens to the Ethereum network. The funds then passed through eight intermediate addresses, where NES was exchanged for ETH on decentralized exchanges.
But then the market intervened. Liquidity in the pools dried up faster than the hacker could realize the entire volume. The slippage turned out to be so devastating that almost nothing remained of the nominal amount. In the end, having spent about $255,000 on preparation, the attacker netted only $315,000—a paltry profit compared to the scale of what was planned.
Ecosystem Response and Threat Scale
Cosmos Labs responded promptly to the incident, recommending that all networks using vulnerable versions of the module (below v0.6.2 or v0.7.2) immediately halt block validation and install patches. The team confirmed that many chains have already addressed the issue, but a detailed report on affected networks and total damage will be published later.
The attack affected at least four networks running on the shared module. In KiiChain, the attacker repeated the exploit 18 times, extracting over 148 million KII tokens. Nesa, MANTRA, and TAC also confirmed hacking attempts and temporarily suspended services for updates.
My analysis: This case is a vivid illustration that the nominal value of stolen assets often has nothing to do with real profit. The market itself acts as a protective mechanism: insufficient liquidity and slippage can turn a "perfect crime" into a loss-making venture. However, the main lesson here is not the size of the hacker's profit, but the systemic vulnerability of Cosmos infrastructure, which requires an immediate review of security protocols by all dependent networks.