← Radar

Incident case file

Sign in to watch

Nesa Chain Cosmos EVM Underflow Exploit — $50M Nominal / ~$60K Net Profit

Incident date Aug 23, 2026Last updated Sep 24, 2026

0 views

ContainedNesaShared Cosmos EVM module vulnerability (GHSA-7g4w-cg88-2cq2), possibly distinct actorCluster: COSMOSEVM-NESA-2026-08

Estimated loss

$60K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

50%

Facts and investigation

Ledger

Attacker

0x9AE755D23Fc948fE94C9364A2398fd508a2AB0d2 (truncated in most sources as 0x9AE7...)

Funds moved to

The attacker bridged approximately $50M in nominal NES back to Ethereum after inflating a balance roughly 200x, then attempted to route proceeds through DEXs and CEXs via a chain of intermediary wallets, but extreme slippage and vanishing liquidity limited actual realized profit to approximately $60,000 (having spent about $255,000 to net $315,000).

Linked

Main wallet (funded via Monero): 0x9AE755D23Fc948fE94C9364A2398fd508a2AB0d2. Two distribution addresses: 0x80c17107E7929e2440c9E528466776ec71329e89 and 0x9b49E12a68185B9b5cC2EC469E9ef43719f51c7c. Blockchain analytics firm Bubblemaps noted the funding method differed from the other chains in this cluster, suggesting a possibly separate actor.

Chronology

1 beat
  1. On August 24, 2026, an attacker exploited the same shared Cosmos EVM underflow vulnerability against Nesa, a chain later identified independently by analytics firm Bubblemaps rather than named directly by Cosmos Labs' own report. The attacker funded a wallet via Monero, purchased approximately $250,000 worth of NES, bridged it to Nesa, exploited the bug to inflate the balance roughly 200-fold, and bridged approximately $50 million in nominal NES back to Ethereum. However, because liquidity had been withdrawn from relevant pools before most of the selling occurred, the attacker faced extreme slippage across the resulting DEX and CEX-routed swaps, netting only approximately $60,000 in real profit against roughly $255,000 spent — a stark contrast between nominal exposure and actual realized gain. Bitvavo suspended NES deposits and withdrawals on August 24 as a precaution. Bubblemaps noted that the funding method for this exploit differed meaningfully from the pattern seen on the other affected chains, raising the possibility that Nesa was targeted by a separate actor exploiting the same underlying bug independently.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)