An attacker exploited a flaw in the Cosmos EVM to move $50 million worth of Nesa (NES) tokens off the Nesa Chain, according to blockchain analytics firm Bubblemaps.
The Cosmos EVM exploit, which surfaced on August 24, 2026, allowed the attacker to artificially inflate a token balance before bridging the funds across chains, but a combination of vanishing liquidity and extreme slippage meant the attacker ultimately walked away with just $60,000.
Bubblemaps’ investigation traced the origins of the Cosmos EVM exploit to a single wallet, 0x9AE7, which purchased $250,000 worth of NES and bridged the tokens to Nesa Chain.
The firm noted that the wallet had been funded through Monero (XMR), a privacy-focused cryptocurrency often used to obscure the source of funds. Once on-chain, the attacker used the Cosmos EVM exploit to inflate that initial balance by 200 times, then bridged roughly $50 million worth of NES back to Ethereum.
How the Cosmos EVM exploit unraveled
From Ethereum, the proceeds of the Cosmos EVM exploit moved through eight separate wallet addresses. Those wallets swapped NES for ETH across decentralized exchanges before attempting to route the funds toward centralized platforms, a common laundering pattern in large-scale crypto hacks.
However, the plan did not go as intended. Liquidity disappeared from the relevant trading pools before the bulk of the selling could take place, and the resulting slippage severely undercut the attacker’s returns.
In the end, the perpetrator recovered just $315,000 against roughly $255,000 in initial costs, a net gain of only $60,000 despite having minted tens of millions of dollars in tokens through the Cosmos EVM exploit.
Cosmos Labs responds to the Cosmos EVM exploit
Cosmos Labs disclosed the incident publicly on August 24 and urged validators on affected chains to halt operations while the Cosmos EVM exploit was contained. The organization has continued to work with impacted networks as patches roll out.
“Many affected chains have now patched. We continue to provide mitigation information to affected chains. Chains that use a Cosmos EVM version less than v0.6.2 or v0.7.2 are recommended to immediately halt the blockchain and upgrade it to include the patches in those releases,” — Cosmos Labs, in a public update.
Cosmos Labs has not yet disclosed the specific nature of the vulnerability behind the Cosmos EVM exploit, the full list of affected chains, or a total estimated loss figure across the ecosystem. The team has said a comprehensive incident report will follow once its response efforts conclude.
Wider fallout across the Cosmos ecosystem
The Cosmos EVM exploit was not confined to Nesa Chain. At least four networks running the same shared module have reported related security problems.
KiiChain said an attacker repeated the exploit technique 18 times, draining 148,326,583.15 KII tokens from its network, a scale far larger than the Nesa incident in raw token terms.
Nesa separately confirmed it had identified malicious activity tied to the Cosmos EVM exploit on its layer-1 network. The project said its services would return online only after a software fix has been fully implemented and verified. Other networks reportedly affected by the same vulnerability include MANTRA and TAC, though the extent of their losses has not been detailed publicly.
Because Cosmos Labs has not yet released a full accounting of the damage, it remains unclear whether additional chains running the vulnerable shared module absorbed quieter losses that have not been reported. Until the promised incident report is published, the true scale of the Cosmos EVM exploit across the broader Cosmos ecosystem will remain uncertain.
For now, the episode stands as a reminder of how quickly cross-chain vulnerabilities can escalate, and how market mechanics, in this case collapsing liquidity, can sometimes blunt the financial impact of even a nine-figure exploit before an attacker can cash out.