Nesa Exploit Leads to Massive NES Token Outflow Amid Cosmos EVM Vulnerability Chain
A single transaction carried away a quarter of Nesa’s token supply to Ethereum.
Full details are still pending.

On August 24, an attacker leveraged a Cosmos EVM vulnerability—previously used against MANTRA, TAC, and KiiChain—to move 257,703,733 NES from Nesa to Ethereum via Hyperlane. This transfer represented approximately 25.8% of NES’s stated total supply.
According to Bubblemaps, the value of the bridged tokens was in the vicinity of $50 million.
Before the exploit, NES was trading close to $0.20. Historical price data from CoinGecko suggests the withdrawal's value was between $50 million and $53 million, based on pre-incident pricing.
Nesa became the fourth chain to be publicly associated with this exploit series, just five days after Cosmos EVM distributed patches described as “important security fixes.” (Release notes here)
Nesa’s official statement only mentioned having "identified malicious behavior", promising to restore services after implementing a fix and additional protections.
This vague response left much unexplained. Who provided clarity in their place?
Credit: Cosmos Labs, Rarma, Bubblemaps, CoinGecko, Grey Ledger, Nesa, MANTRA, KiiChain, TAC, bitvavo
Nesa’s statement was the first to arrive, but revealed very little.
In the early hours of August 24, Nesa’s team indicated it had detected malicious activity exploiting a Cosmos EVM bug, said mitigation steps were underway, and pledged to restore services after a software fix. Exchanges were reportedly notified. There was no mention of the exploit’s mechanism, attacker’s wallet, affected accounts, or estimated losses.
Nesa’s public API endpoints returned 503 errors for hours following the announcement. With the explorer and RPC endpoints unavailable, external observers were unable to analyze on-chain activity related to the incident.
As of September 8, the public block explorer remained unusable, displaying 0% uptime and no block data.
Without access to an explorer or RPC endpoint, outside parties could not review transactions or state changes related to the exploit.
Ethereum records, however, remained accessible. Nesa’s miner-rewards script was configured to use Hyperlane Nexus as its default NES bridge, and Hyperlane’s documentation designates Nesa as domain 41443.
The Hyperlane bridge on Ethereum logged 257,703,733.288579599652028616 NES arriving from Nesa to an address under attacker control.
Rarma reconstructed the bridge activity: The attacker deposited 1,114,564.66 NES into Nesa between 03:13 and 04:12 UTC, and subsequently received 257,703,733 NES via Hyperlane on Ethereum.
This left a discrepancy of about 256.6 million NES. The gap highlights a massive bridge imbalance, but does not conclusively identify the precise call or method used on the Nesa side.
The withdrawal, over 230 times the attacker’s initial deposit, was observable on Ethereum even before Nesa had disclosed any figures.
Rarma noted the limitations of his reconstruction, citing the inability to confirm the exact precompile involved due to Nesa’s node outages.
The pattern matched earlier attacks on Cosmos EVM chains—same vulnerability, same ecosystem, and similar bridge outflow.
Cosmos Labs’ postmortem on August 28 later confirmed six networks were breached via this vulnerability chain, explicitly naming only MANTRA, TAC, and KiiChain; Nesa was not specifically listed.
If three networks can specify the exact call that drained them and another cannot, does that reflect a difference in the incident or just in disclosure?
Confirmations from Other Sources
The vulnerability exploited on Nesa was not new.
On May 13, Cosmos Labs submitted a pull request titled “fix: harden statedb balance and event amount handling.” The stated aim was to prevent StateDB balance underflow and ensure event parsing was denomination-aware. The patch was merged to the main branch two days later.
The proof of concept targeted a six-decimal network. Cosmos Labs reported that attempts to reproduce the issue on 18-decimal networks failed, leading to the mistaken belief that production funds were not at risk—despite all live Cosmos EVM networks using 18 decimals.
This led Cosmos Labs to implement what they called a "silent patch" process, with the fix merged on May 15. The patch was public but the vulnerability was not disclosed.
The exploit involved chaining two balance-accounting bugs. A vesting account could delegate locked coins using the EVM staking precompile, even if those coins were not spendable in the Cosmos EVM balance view.
However, StateDB tracked only spendable balances; delegating more than this amount caused an underflow, making the EVM-visible balance nearly 2^256.
Sending 2^256 minus the victim's balance to that address zeroed its balance, and the attacker took over the original funds. By deploying a contract at a deterministic address first converted to a vesting account, both underflow and overflow could be triggered in one transaction.
On August 19, Cosmos Labs backported the fixes to v0.6.x and v0.7.x, opting for an obscured release to reduce attacker awareness.
These patches were released as v0.6.2 and v0.7.2, with notes referencing only “important security fixes,” omitting details about the vulnerability, CVE assignment, or user fund risk.
The following day, MANTRA was exploited, with TAC and KiiChain targeted two days after.
On KiiChain, the report describes 148.3 million KII withdrawn over 18 exploit iterations.
No similar technical breakdown was published for Nesa; there was no public postmortem with a Nesa-side CreateVestingAccount transaction, staking-precompile call, or identification of the victim account.
Cosmos Labs stated that six networks were breached through the vulnerability chain, but provided detailed accounts only for three, omitting the others “for brevity.”
Nesa’s incident disclosure and the Ethereum bridge evidence suggest it was among the unnamed affected networks, though Cosmos Labs did not explicitly confirm this or provide Nesa-specific transaction data.
Is the difference between Nesa and the other affected chains the nature of the incident, or simply the level of transparency?
Market Impact and Attacker Proceeds
The figure featured in headlines was not the same as the attacker’s actual gains.
A Hyperlane transaction delivered 257,703,733 NES to an attacker-owned Ethereum wallet, identified by Rarma as the main attacker address.
Bubblemaps assessed this position at roughly $50 million on Ethereum at the time.
The attacker faced a collapsing market while attempting to liquidate these holdings.
NES’s price plunged from $0.195893 on August 23 to $0.01347432 by the end of August 24.
At 13:40 UTC, the attacker’s wallet burned 25 million NES.
The burn transaction was not processed on Nesa’s chain before it halted. If the chain restarts without rolling back before the message, Rarma noted that another Hyperlane delivery could mint the 25 million NES unless Hyperlane intervenes.
The attacker then sold the remainder. Rarma tracked sales between 15:11 and 16:09 UTC from a different Ethereum wallet, which was funded by the main attacker address.
A total of 185,744,335 NES were sold across 241 trades via CoW Protocol and Uniswap V4. The average price fell from $0.0125 to $0.00032 during the liquidation.
Rarma calculated that the sales brought in 95.97 ETH, worth about $237,208 at the time.
These sales plus the burn account for approximately 210.7 million of the 257.7 million NES withdrawn, leaving around 47 million NES unaccounted for.
With Nesa’s chain still offline, the fate of these remaining tokens is unclear.
Bridge Withdrawal on Ethereum (257,703,733 NES): 0xd443eabd4cfa1be6ad5f7ef861db9a9f271305040615667ed336bc195af05080
Attacker’s Ethereum Wallet: 0x9AE755D23Fc948fE94C9364A2398fd508a2AB0d2
Burn Transaction (25,000,000 NES): 0x575d6cc254ed1e9313bbb0fdc93c1bda937993dbe8b9b7db8a85911166c2e26d
Sales Wallet: 0xB92dF70F3d25eD25265c7C341C9D2550c42Ff83A
Bubblemaps later estimated the attacker’s operational costs at $255,000 and sale proceeds at $315,000, for a net profit of approximately $60,000.
They also noted that the attacker's funding originated from Monero and routed through multiple wallets before conversion to ETH and deposit on centralized exchanges.
These figures depend on Bubblemaps’ own attribution and cost calculations and do not represent a confirmed payout.
A single transaction bridged a quarter of the NES supply in one go.
Ultimately, the attacker’s realized gains depended on available liquidity after the incident, not the token’s pre-exploit price.
What does the headline theft amount mean when it neither reflects the attacker’s profit nor the market’s true absorptive capacity?
Lack of Technical Disclosure

MANTRA published a technical postmortem on August 28, eight days after halting its chain on August 20.
KiiChain’s technical postmortem came out one day after its August 22 exploit, specifying the exploit steps, attacker infrastructure, and individual exploit rounds. It also separated losses immobilized on KiiChain from those bridged to BNB Chain. Their report criticized Cosmos Labs’ disclosure process and the lack of an earlier halt recommendation.
TAC initially deferred its postmortem and relaunch following a request from Cosmos Labs, pending network patching.
On September 2, TAC finally published a technical postmortem and recovery plan, detailing the compromised staking pool, exploit transaction, attacker’s bridge/sale flow, and a path to recovery.
Nesa has not set a public timetable for a technical report or restart. Their August 24 statement only promised that services would resume "after applying a software fix and further remedies."
No date was subsequently provided. There has still been no public identification of the loss amount, attacker wallet, transaction breakdown, or technical exploit path.
A September 5 update called the breach a "pre-meditated set of operations" using "a widely used attack vector," stated that the chain was "fully patched with direct support from the official upstream code maintainers," and said exchanges would open deposits and trading "this week." No further technical details, wallet addresses, or loss totals were disclosed.
Exchange updates came sooner. On August 24, bitvavo suspended NES deposits and withdrawals, citing a “critical consensus vulnerability” that caused affected nodes to accept invalid blocks.
While this was not a technical postmortem, it provided customers with more operational detail than Nesa had made public.
Cosmos Labs’ postmortem on August 28 confirmed six networks were exploited, but granular transaction-level detail was provided only for MANTRA, TAC, and KiiChain; the rest were omitted for brevity.
Nesa’s public disclosures and the Ethereum bridge record suggest it was one of the unnamed affected networks, though Cosmos Labs never confirmed this directly.
What does it indicate when, even after multiple follow-ups, a chain’s public commentary on a bridge-out of a quarter of its supply stops at general containment language?
One transaction silenced Nesa’s communications, but did not resolve the underlying issue.
Nesa stated only that it had “identified malicious behavior,” with further details coming from Ethereum and third-party analyses. The technical root cause was explained by Cosmos Labs’ postmortem, which acknowledged six affected networks but did not name or detail Nesa’s case specifically.
MANTRA, KiiChain, and TAC ultimately published detailed explanations.
Cosmos Labs confirmed six networks were compromised, but provided full timelines only for three, citing brevity for the omissions.
Nesa’s statements and the Ethereum bridge record are consistent with it being among the unlisted affected chains, though this remains unconfirmed.
A quarter of Nesa’s token supply moved across a bridge in a single transaction.
What responsibility does a Cosmos EVM chain have to holders when the most comprehensive public record of a major loss comes from outside the project itself?
Get new scam files the moment we publish them — usually 2–3 emails a week.