Cosmos EVM Security Flaw Exposed: Nesa Chain Hit for $50M
A security flaw in the shared Cosmos EVM stack has been exploited on Nesa Chain, allowing an attacker to create and bridge approximately $50 million worth of NES tokens to Ethereum. Despite the enormous nominal value of the position, collapsing liquidity meant the attacker appears to have made only about $60,000 in net profit.
The incident is part of a wider security problem affecting several networks that use Cosmos EVM, a framework designed to bring Ethereum-compatible smart contracts and tooling to Cosmos SDK chains. The official Cosmos EVM repository describes the framework as a plug-and-play EVM layer used across multiple blockchain projects.
Nesa Attacker Inflated Balance 200-Fold: The attack reportedly began with wallet 0x9AE7, which acquired roughly $250,000 of NES before bridging the tokens to Nesa Chain. Blockchain analytics firm Bubblemaps traced the wallet's initial funding to Monero. After exploiting the vulnerability, the attacker increased the NES balance by around 200 times and bridged approximately $50 million in tokens back to Ethereum.
The assets were then split across eight wallets, exchanged for ETH through decentralized exchanges and sent toward centralized platforms. However, liquidity disappeared as the wallets attempted to sell, producing severe slippage. The attacker spent about $255,000 and recovered approximately $315,000, leaving a gain near $60,000.