Cosmos EVM Flaw Exploited on Nesa; KiiChain, TAC, and MANTRA Also Impacted

AI مارکیٹ کا خلاصہ
A shared Cosmos EVM vulnerability was exploited on Nesa and has triggered chain halts and upgrades across multiple Cosmos SDK networks (including KiiChain, TAC, and MANTRA), highlighting systemic smart-contract and bridge risk in a common codebase. Although realized attacker profits were limited by collapsing liquidity, the incident can pressure affected tokens via confidence and liquidity impacts, while increasing scrutiny of cross-chain infrastructure and operational resilience.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
MANTRA/USDT+3.06%
AI تجزیاتی سمجھ · MANTRA/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A vulnerability in the shared Cosmos EVM codebase has been exploited on Nesa Chain, enabling an attacker to mint and bridge roughly $50 million worth of NES tokens to Ethereum. Despite the headline figure, drained liquidity and heavy slippage appear to have limited the realized profit to about $60,000. Cosmos EVM is a plug-and-play EVM layer used by multiple Cosmos SDK chains to support Ethereum-compatible smart contracts and tooling, increasing the blast radius when shared components fail. On-chain traces suggest the attack began from wallet 0x9AE7, which accumulated about $250,000 of NES before bridging to Nesa Chain. Analytics firm Bubblemaps linked the wallet's initial funding to Monero. After exploiting the flaw, the attacker inflated the NES balance by roughly 200x, bridged around $50 million back to Ethereum, split the proceeds across eight wallets, swapped tokens for ETH on decentralized exchanges, and routed funds toward centralized platforms. Execution constraints undercut the payout. As the wallets attempted to sell, liquidity collapsed, worsening slippage. The attacker reportedly spent about $255,000 and recovered around $315,000, for an estimated net gain near $60,000. Nesa is not the only network exposed. Cosmos Labs advised chains running vulnerable Cosmos EVM versions to halt and upgrade while mitigations are developed. Multiple projects have since disclosed related incidents, including KiiChain, TAC, and MANTRA. KiiChain reported the exploit method was repeated 18 times, draining 148,326,583.15 KII before validators halted the chain. TAC paused operations after an attacker drained an account. MANTRA had previously halted, then resumed after deploying a fix. The incident adds to an active year for crypto exploits. Coinpaper's latest hack report estimates about $247.4 million was stolen in July alone, with bridges remaining a recurring target. A more recent SAND incident also involved unauthorized token minting across cross-chain infrastructure. Cosmos EVM has faced critical issues before. A March advisory described a state-handling flaw that could allow repeated use of token balances during nested EVM execution; that bug was patched in version 0.6.0. The root cause of the latest incident has not yet been publicly detailed.