Cosmos EVM Exploit Yields Meager Profits for Attackers Amid Liquidity Crunch
A critical vulnerability in the Cosmos EVM stack has been exploited on multiple blockchain networks. The incident began on Nesa Chain, where an attacker bridged roughly $50 million worth of NES tokens to Ethereum after inflating their balance by around 200 times. Despite the enormous nominal value of the position, collapsing liquidity meant the attacker made only about $60,000 in net profit.
The attack started with wallet 0x9AE7, which acquired approximately $250,000 of NES before bridging the tokens to Nesa Chain. The initial funding for this wallet was traced to Monero by blockchain analytics firm Bubblemaps.
This is not an isolated incident - several other chains running vulnerable Cosmos EVM versions have been affected, including KiiChain, TAC and MANTRA. These networks have either halted or paused operations while mitigation work continues.