Bubblemaps said on X that an attacker exploited a vulnerability in the shared Cosmos EVM module to steal $50 million worth of NES tokens, but ultimately made only about $60,000.
Cosmos Labs had previously reported a security flaw in its shared Cosmos EVM software. Several chains built on that module were affected, including Nesa.
How the attack unfolded
According to the disclosure, the main attacker used a wallet address beginning with 0x9AE7. That address first spent $250,000 to acquire NES and bridged the tokens to Nesa Chain. The attacker then used the flaw to inflate the account balance by 200x and bridged $50 million worth of NES back to Ethereum. Bubblemaps said the wallet’s original funding came from Monero.
The attacker later split the tokens across multiple wallet addresses, swapped NES for ETH on decentralized exchanges, and moved the proceeds to centralized exchanges.
Large theft, small realized gain
While the nominal value of the stolen NES reached $50 million, the attacker was unable to cash out anywhere close to that amount. Liquidity was removed from the pool quickly, and most of the swaps ran into severe slippage.
Based on figures shared by Bubblemaps, the attacker spent $255,000 to carry out the operation and realized only $315,000 in proceeds, for a net profit of about $60,000.
Similar exploit on another chain may be unrelated
Bubblemaps also said another Cosmos EVM chain had suffered a similar $1.4 million exploit the day before. Still, differences in funding sources and operational patterns suggest the two incidents may have been carried out by different attackers.
NES fell 90% before rebounding
The report said the NES token at one point dropped 90%, then recovered sharply. The team said the rebound was mainly driven by arbitrage tied to price dislocations between decentralized exchanges and centralized exchanges after the attack.

