The Cosmos EVM exploit wave has a fourth publicly identified victim: Nesa, an AI-focused network from which an attacker withdrew 257,703,733 NES — roughly 25.8% of the token's stated supply — through Hyperlane to Ethereum on August 24.

Bubblemaps estimated the bridged position at about $50 million; CoinGecko's historical data, with NES trading near $0.20 before the crash, places the withdrawal in the $50–53 million range. The same Cosmos EVM vulnerability chain had already hit MANTRA, TAC, and KiiChain.

What separates Nesa from the other three chains is not the loss. It is the silence.

A Statement That Explains Nothing

Nesa's own announcement arrived first, on August 24: the team had "identified malicious behavior" exploiting a Cosmos EVM vulnerability, exchanges had been notified, and services would return after a fix. It named no mechanism, no attacker wallet, no affected accounts, and no loss figure.

In the hours that followed, Nesa's public endpoints began returning 503 errors. Without a working explorer or RPC endpoint, outsiders could not inspect the source-chain transactions behind the withdrawal. As of September 8 — more than two weeks later — the public explorer still returned no usable block data and reported 0% uptime.

What the Ethereum Side Shows

What remained inspectable was Ethereum. Nesa's own tooling configured Hyperlane Nexus as its default NES bridge, and Hyperlane's registry assigns the network domain 41443. The delivery transaction on Etherscan shows 257,703,733 NES arriving from Nesa to an attacker-controlled Ethereum address.

Researcher Rarma reconstructed the observable flow from those records: the attacker acquired and deposited 1,114,564.66 NES into Nesa between 03:13 and 04:12 UTC, then received 257.7 million NES on Ethereum — a withdrawal more than 230 times the deposit. That gap establishes the scale of the bridge imbalance, though with Nesa's nodes down, even Rarma could not confirm which Cosmos EVM precompile the attacker actually used.

The Count That Doesn't Include Nesa

Cosmos Labs' August 28 post-mortem confirmed that six networks were exploited through the shared vulnerability chain between August 20 and 25 — but it named only MANTRA, TAC, and KiiChain outright. Nesa was not included in that count.

The patch itself had shipped five days before Nesa's exploit, described only as containing "important security fixes" — state-breaking fixes whose severity was, by Cosmos Labs' own admission, misjudged after the underlying balance-underflow bug was first flagged in May.

The market absorbed the damage regardless: Bubblemaps estimates slippage cut the attacker's realized profit to roughly $60,000. A quarter of the supply was stolen, and almost nothing was banked — the crash destroyed the attacker's own loot along with everyone else's holdings.

If three chains can point to the exact call that drained them and a fourth cannot, the difference is not in what happened — it is in who bothered to say. Nesa's disclosure failure is now part of the incident's cost: the community is left reconstructing a nine-figure theft from the destination chain's records while the source chain's own data stays dark.

TrustGrade tracks disclosure quality as part of project trust. For verified trust data on the projects and firms shaping it, see trustgrade.ai.