Hacker Minted $50M in Crypto and Walked Away With $60K: The Worst Heist in DeFi History
A hacker successfully exploited the Cosmos EVM to mint $50 million worth of Nesa (NES) tokens — and somehow left with just $60,000.
That is not a typo. The attacker pulled off a technically sophisticated exploit, moved a nine-figure position, and then watched liquidity pools drain dry before they could cash out. The result: a 99.9% loss on the most expensive trade they never meant to make.
What Actually Happened
The attacker found a vulnerability in the Cosmos EVM layer connected to the Nesa blockchain. Using that flaw, they minted NES tokens worth $50 million on paper — a position that would have made this one of the largest DeFi exploits of the year.
But paper gains are not real gains. The moment selling began, liquidity vanished from the pools. Every sell order cratered the price further, triggering extreme slippage that swallowed almost the entire position before the attacker could exit.
Blockchain analytics firm Bubblemaps traced the wallets involved and laid out exactly how the heist collapsed in real time. The token's liquidity simply could not absorb a $50 million dump. By the time the dust settled, $60,000 was all that remained.
Why This Matters Beyond the Punchline
The Nesa exploit is funny until it isn't. Yes, the hacker failed spectacularly. But the vulnerability was real, the mint was real, and $50 million in token value evaporated in the chaos — value that legitimate NES holders watched disappear.
This is also a warning shot for every low-liquidity altcoin sitting on Cosmos-adjacent infrastructure. If a single exploit can drain pools this fast, the safety net for token holders is thinner than most projects admit. Deep liquidity is not a marketing metric. It is the difference between a near-miss and a total collapse.
For the attacker, the lesson is almost poetic: minting tokens means nothing without an exit. The exploit worked. The trade did not.
What to Watch Now
Bubblemaps has the wallet trail, which means on-chain investigators are still active on this case. Watch for whether the $60,000 that was extracted gets flagged and frozen through exchange KYC processes — that would close the loop entirely.
More importantly, if you hold tokens on any low-liquidity Cosmos EVM chain, now is the time to check the depth of those liquidity pools. Thin markets are not just a price risk. As Nesa just proved, they are a security risk.
The hacker came for $50 million. The market gave them a lesson instead.