BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Cosmos EVM Security Flaw Hits Nesa, KiiChain, TAC and MANTRA Networks

A vulnerability in the shared Cosmos EVM stack has been exploited on Nesa Chain, allowing an attacker to create and bridge roughly $50 million worth of NES tokens to Ethereum. Despite the eno

AnonymousCryptoCompass newsroom
August 27, 2026
2 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

A vulnerability in the shared Cosmos EVM stack has been exploited on Nesa Chain, allowing an attacker to create and bridge roughly $50 million worth of NES tokens to Ethereum. Despite the enormous nominal value of the position, collapsing liquidity meant the attacker appears to have made only about $60,000 in net profit.

The incident is part of a wider security problem affecting several networks that use Cosmos EVM, a framework designed to bring Ethereum-compatible smart contracts and tooling to Cosmos SDK chains. The official Cosmos EVM repository describes the framework as a plug-and-play EVM layer used across multiple blockchain projects.

Nesa Attacker Inflated Balance 200-Fold

The attack reportedly began with wallet 0x9AE7, which acquired roughly $250,000 of NES before bridging the tokens to Nesa Chain. Blockchain analytics firm Bubblemaps traced the wallet’s initial funding to Monero.

After exploiting the vulnerability, the attacker increased the NES balance by around 200 times and bridged approximately $50 million in tokens back to Ethereum. The assets were then split across eight wallets, exchanged for ETH through decentralized exchanges and sent toward centralized platforms.

The headline figure, however, overstated what the attacker could actually realize. Liquidity disappeared as the wallets attempted to sell, producing severe slippage. The attacker spent about $255,000 and recovered approximately $315,000, leaving a gain near $60,000.

Shared Cosmos EVM Code Puts Multiple Chains at Risk

Nesa is not the only affected network. Cosmos Labs advised chains running vulnerable Cosmos EVM versions to halt and upgrade while mitigation work continues. Several chains have already disclosed incidents, including KiiChain, TAC and MANTRA.

KiiChain said an attacker repeated the exploit technique 18 times, draining 148,326,583.15 KII before validators stopped the chain. TAC also halted after an attacker drained an account, while MANTRA previously paused operations and later resumed after applying a fix.

The episode arrives amid an unusually active year for crypto exploits. July alone saw about $247.4 million stolen across crypto platforms, with bridges remaining a frequent target in Coinpaper’s latest hack report. A more recent SAND exploit similarly involved unauthorized token minting across cross-chain infrastructure.

Cosmos EVM has faced critical vulnerabilities before. A March security advisory detailed an earlier state-handling flaw that could allow repeated use of token balances during nested EVM execution; that issue was patched in version 0.6.0. The precise root cause of the latest incident has not yet been publicly detailed.