Cosmos EVM Exploit: $50M NES Mint on Nesa Chain Yields Attacker Only $60,000; KiiChain and TAC Halted
Key Takeaways
- •The attacker began with a wallet that bought about $250,000 of NES and later used the exploit to inflate the token balance 200-fold.
- •Roughly $50 million in NES was bridged to Ethereum and spread across eight wallets before being swapped for ETH.
- •Despite the large token value involved, the operation is estimated to have produced only about $60,000 in net profit because of slippage and falling liquidity.
- •Cosmos Labs told projects using the exposed Cosmos EVM version to pause their chains and apply the required upgrades.
- •KiiChain said the attacker repeated the process 18 times and stole 148,326,583.15 KII, while TAC halted operations after one of its accounts was compromised.

An attacker exploited a vulnerability in Cosmos EVM to create and bridge roughly $50 million worth of NES tokens through Nesa Chain, but collapsing liquidity limited the operation's estimated net profit to approximately $60,000 during the sales.
The incident also underscored the vulnerabilities facing other networks built on the same architecture. Cosmos EVM enables the use of Ethereum-compatible smart contracts on chains built with the Cosmos SDK.
How Did the Cosmos EVM Exploit Yield Only $60,000?
The attack began when the wallet 0x9AE7 purchased around $250,000 of NES and transferred the tokens to Nesa Chain. Blockchain analytics platform Bubblemaps traced the wallet's original funding to Monero.
JUST IN: A Cosmos EVM vulnerability was exploited to mint and bridge roughly $50M worth of NES from Nesa Chain, but the attacker reportedly made only around $60K due to extreme slippage and liquidity withdrawals. pic.twitter.com/DU2txNRBRB
— EyeWhales (@EyeWhales) August 27, 2026
The attacker then exploited the vulnerability to multiply the NES token balance by 200 before moving $50 million of the tokens to Ethereum. The tokens were subsequently distributed across eight wallets.
The attacker swapped NES for ETH on decentralized exchanges and then moved the funds onward to centralized exchanges. Liquidity dried out during the swapping process, however, and the attacker was subjected to significant slippage.
That gap reflects how automated market makers price assets: pools quote tokens against the depth of liquidity they hold, so large sell orders push prices down as they execute, and paper value evaporates once that depth is withdrawn. A freshly minted balance is therefore worth only what the remaining pools will actually pay.
The operation is estimated to have cost $255,000 while generating $315,000 in gains, meaning the hacker cleared roughly $60,000 despite briefly controlling tokens worth nearly $50 million.
Cosmos Labs Urges Affected Chains to Pause and Upgrade
The event triggered a wider response because the vulnerable Cosmos EVM software affects networks beyond Nesa. Cosmos Labs advised other projects utilizing the exposed version to pause their chains and complete the required upgrades.
According to KiiChain, the attacker repeated the same process 18 times and stole 148,326,583.15 KII before validators took the network down. The TAC chain also halted its operations after one of its accounts was compromised.
Halting block production is a standard emergency measure on Cosmos SDK networks, where a coordinated validator majority can stop transaction processing while a fix is prepared — the response KiiChain's validators and TAC ultimately carried out.
The incidents highlight how shared code allows a single security issue to affect several ecosystems. Losses from such attacks vary depending on local token liquidity, bridge availability, exchange liquidity, and the speed of the validator response.
Why the Cosmos EVM Exploit Remains Unclear
The attack took place amid heightened cyberattack activity targeting cryptocurrencies. In July, crypto exchanges incurred losses worth $247.4 million, with bridges proving to be popular targets. In another recent incident, SAND tokens were minted without authorization through cross-chain bridges.
#PeckShieldAlert Seems like The @TheSandboxGame ( $SAND ) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR
— PeckShieldAlert (@PeckShieldAlert) August 22, 2026
In March, a security advisory outlined a critical issue concerning state management. The vulnerability would have allowed token balances to be reused while executing EVM transactions, and it was fixed through the deployment of version 0.6.0 of the software.
The connection between that earlier vulnerability and the current Cosmos EVM hack has not been verified, and it remains unclear how many networks have been affected. Those questions are expected to be answered only once a detailed technical report is issued. Funds that pass through centralized exchanges are typically easier to trace than on-chain swaps and can be frozen at the platform level, which is why the movement of proceeds to CEXs is often where post-incident response efforts concentrate.
Source: Tron Weekly