Crypto news report · source clearly identified

Cosmos EVM Exploit Moves $50 Million of Nesa Tokens, Yields Only $60 K for Attacker

A vulnerability in the Cosmos EVM allowed an attacker to mint and bridge roughly $50 million worth of Nesa (NES) tokens, but extreme slippage and liquidity loss limited the net proceeds to about $60 000.

An attacker exploited a flaw in the Cosmos EVM to inflate a wallet’s Nesa (NES) balance and move the tokens across chains. Although the operation involved roughly $50 million of NES, the final payout was only about $60 000 after severe slippage and liquidity depletion.

How the Exploit Unfolded

The main wallet (0x9AE7) initially purchased $250 000 of NES and bridged the tokens to the Nesa Chain. Blockchain analytics firm Bubblemaps traced funding for this address to Monero (XMR). The attacker then used the vulnerability to inflate the NES balance by a factor of 200, bridging roughly $50 million of NES back to Ethereum.

From Ethereum, the tokens passed through eight intermediate addresses, where they were swapped for ETH on decentralized exchanges. The proceeds were subsequently routed to centralized platforms. However, liquidity in the pools vanished before most of the selling could occur, causing extreme slippage that ate up the majority of the position.

Financial Outcome

  • Attacker spent approximately $255 000 on swaps.
  • Recovered about $315 000, resulting in a net gain of roughly $60 000.

Response from Cosmos Labs

Cosmos Labs disclosed the incident on August 24 and advised all chains using the affected Cosmos EVM versions (

Source & attribution

News Source

Publisher
BeInCrypto
Original date
August 27, 2026, 5:50 AM
Original headline
Cosmos EVM Hacker Minted $50 Million — and Walked Away With Just $60,000
View original report ↗