Cosmos EVM Hacker Minted $50 Million — and Walked Away With Just $60,000

  • An attacker bridged $50 million of NES off Nesa Chain and made only $60,000.
  • Bubblemaps traced the funds through eight wallets tied to a Monero-funded address.
  • Cosmos Labs told EVM chains to halt after its August 24 disclosure.
Promo

An attacker exploited a vulnerability in the Cosmos EVM to move $50 million of Nesa (NES) off the project’s chain. However, the payout came to $60,000.

Blockchain analytics firm Bubblemaps traced the wallets involved. Liquidity vanished from the pools before the selling finished, and extreme slippage swallowed almost the entire position.

Sponsored
Sponsored

How the Nesa Exploit Unraveled

The main wallet, 0x9AE7, bought $250,000 of NES and bridged the tokens to Nesa Chain. Bubblemaps said the address was funded through Monero (XMR).

The attacker exploited the bug, inflating that balance by 200 times. He then bridged roughly $50 million of NES back to Ethereum (ETH).

From there, the tokens moved through eight addresses. Those wallets swapped NES for ETH on decentralized exchanges before routing proceeds to centralized platforms.

However, liquidity disappeared from the pools before most of the selling happened. The swaps hit extreme slippage, and the attacker recovered $315,000 against $255,000 spent.

Follow us on X to get the latest news as it happens

Sponsored
Sponsored

Cosmos Labs Told Chains to Halt

Cosmos Labs disclosed the incident on August 24 and advised chains in contact with it to have validators halt.

“Many affected chains have now patched. We continue to provide mitigation information to affected chains. Chains that use a Cosmos EVM version less than v0.6.2 or v0.7.2 are recommended to immediately halt the blockchain and upgrade it to include the patches in those releases,” the team said in an update.

It has not yet named the vulnerability, the affected chains, or the total loss figure. The team has promised an incident report once the response ends.

Four networks running the shared module have reported problems. KiiChain said an attacker repeated the same technique 18 times, draining 148,326,583.15 KII.

Nesa also notified users that it had identified malicious activity exploiting the Cosmos EVM vulnerability on its layer-1. The team said they will bring the services online after a software fix. Other impacted networks include MANTRA and TAC.

Whether other chains running the module took quieter losses will not be clear until Cosmos Labs publishes its report.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights


To read the latest cryptocurrency market analysis from BeInCrypto, click here.

Disclaimer

BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Sponsored
Sponsored