August 27, 05:50
Cosmos EVM hacker mints $50 million but recovers just $60,000
Cosmos EVM Hacker Minted $50 Million -- and Walked Away With Just $60,000
Beincrypto
An attacker exploited a vulnerability in the Cosmos EVM and inflated a Nesa token balance by 200 times. The attacker moved $50 million of Nesa tokens back to Ethereum. The attacker recovered $315,000 from the trades. The attacker spent $255,000. The resulting difference was $60,000. Bubblemaps traced the wallets involved. The main wallet, 0x9AE7, bought $250,000 of Nesa tokens and bridged them to Nesa Chain. Bubblemaps said Monero funded the address. The tokens moved through eight addresses. Those wallets exchanged Nesa for Ethereum on decentralized exchanges before sending the proceeds to centralized platforms. Liquidity disappeared from the pools before most of the selling happened. Extreme slippage reduced the value recovered. Cosmos Labs disclosed the incident on August 24. Cosmos Labs advised chains using Cosmos EVM versions below v0.6.2 or v0.7.2 to halt immediately and upgrade to patched releases. Cosmos Labs said many affected chains had patched and that it was continuing to provide mitigation information. Cosmos Labs has not named the vulnerability, the affected chains, or the total loss figure. Cosmos Labs plans to publish an incident report after the response ends. Four networks using the shared module have reported problems. KiiChain said an attacker used the same technique 18 times and drained 148,326,583.15 KII. Nesa said malicious activity exploited the Cosmos EVM vulnerability on its layer-1. Nesa plans to restore services after a software fix. MANTRA and TAC were also identified as impacted networks. The impact on other chains will remain unclear until Cosmos Labs publishes its report.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.