A hacker exploited a vulnerability in the EVM module of Cosmos to move $50 million in NES tokens from Nesa Chain to Ethereum, although the actual haul barely reached $60,000 due to liquidity collapse in the pools.
Blockchain analytics firm Bubblemaps traced the funds through eight wallets linked to an address funded via Monero, a privacy-oriented cryptocurrency.
1/ An investigation into how Cosmos attackers stole $50M in $NES using a sophisticated balance exploit, and only made $60k
🧵 pic.twitter.com/KGpDqpgTVn
— Bubblemaps (@bubblemaps) August 26, 2026
The main wallet, identified as 0x9AE7, acquired $250,000 in NES and transferred them to Nesa Chain, where the attacker inflated that balance 200 times before bridging the tokens back.
When attempting to sell on decentralized exchanges, extreme slippage consumed nearly the entire position, leaving a net gain of just $60,000 against the $255,000 invested.
Cosmos Labs disclosed the incident and recommended that affected chains halt their validators immediately. The Cosmos team instructed any network running a module version below v0.6.2 or v0.7.2 to halt and apply the corresponding patches.
Four networks reported issues: KiiChain documented 18 repeated attacks that drained more than 148 million KII, while MANTRA, TAC and Nesa itself confirmed they recorded malicious activity.
The definitive Cosmos report detailing vulnerabilities and total losses is still pending.
Source:Â https://x.com/bubblemaps/status/2092613204396650888
Disclaimer:Â Crypto Economy Flash News are based on verified public and official sources. Their purpose is to provide fast, factual updates about relevant events in the crypto and blockchain ecosystem.
This information does not constitute financial advice or investment recommendation. Readers are encouraged to verify all details through official project channels before making any related decisions.



