Recently, a significant event shook the Cosmos ecosystem with a hack that resulted in 50 million dollars being stolen. By exploiting a vulnerability in the EVM of Cosmos, an attacker was able to move a substantial amount of Nesa (NES) tokens. However, despite the magnitude of this theft, the recovered loot ultimately amounted to only 60,000 dollars. This incident highlights the risks associated with blockchains and the difficulties faced by projects in securing their infrastructures.
The hack began with the hacker purchasing a considerable sum of 250,000 dollars in NES tokens from the main wallet identified as 0x9AE7. This address was funded via the quasi-anonymous Monero (XMR). Once the tokens were transferred to the Nesa Chain, the attacker successfully exploited a vulnerability in the EVM, multiplying their balance by 200.
The implementation of the plan
Through this hack, around 50 million dollars in NES were transferred to Ethereum (ETH). At this point, the funds circulated through eight different addresses, with wallets using decentralized exchanges to trade NES for ETH. However, before most of the sales could be finalized, liquidity completely disappeared from the pools, causing significant slippage in transactions.
This significant slippage resulted in a substantial reduction in the amount recovered by the attacker, who netted around 315,000 dollars for the 255,000 dollars initially invested. This abrupt reversal illustrates the dangers associated with the volatility of cryptocurrencies and trading on decentralized platforms.
The consequences of the attack
Following this incident, Cosmos Labs took immediate measures to protect other affected chains. On August 24, the company revealed the incident and advised the affected chains to ask their validators to cease operations to prevent further exploitation of the vulnerability. Chains using an EVM version lower than v0.6.2 or v0.7.2 were advised to update their systems to eliminate this vulnerability.
Response from the affected chains
Many chains impacted by this attack have now patched the vulnerability and implemented the necessary updates. However, the specific vulnerability exploited and the total losses have not yet been revealed by the security teams at Cosmos. A more in-depth investigation is underway to assess the real impacts and prepare a detailed report on this incident once the crisis is under control.
Four networks using the shared module reported encountering similar issues. KiiChain, for example, mentioned that an attacker had used the same technique multiple times, draining a considerable total of over 148 million KII tokens. This situation demonstrates that the threat of hackers remains ever-present in the blockchain space.
Current situation of Nesa and other affected networks
Nesa also communicated to its users that malicious activity exploiting the vulnerability of the Cosmos EVM had been detected on its Layer-1. The team is currently working on a software patch, promising that services will be brought back online once the situation stabilizes. Other networks like MANTRA and TAC have also been impacted, drawing attention to the security challenges faced by many blockchain projects in this constantly evolving digital era.







