Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Cosmos Secures 1.23 Million Stolen ATOM, Awaits Governance Vote on Distribution

Cosmos Hub validators halted their network and deployed an emergency software patch to intercept 1.23 million ATOM stolen during a September 22 Neutron governance attack. The funds are now held in a six-validator multisig wallet pending a Hub governance proposal to authorize their release.
5 hours ago 18 views
Cosmos Secures 1.23 Million Stolen ATOM, Awaits Governance Vote on Distribution

Validators on the Cosmos Hub secured approximately 1.23 million ATOM following a September 22 governance attack on Neutron that compromised administrative controls over protocols including Astroport. An attacker moved roughly 1.73 million stolen ATOM from Neutron to the Cosmos Hub, where the network's validators took emergency action to prevent further outflows.

The Hub itself was not compromised; it became the venue where intercepted funds could still be retrieved. As the attacker swapped and bridged ATOM, Hub validators halted the chain at height 33,086,740 and coordinated a restart using a patched version of the Gaia software, v28.3.0. A one-time state change transferred 1,227,121.37 ATOM from the attacker-controlled address to a recovery multisig before normal transactions resumed. Validators representing more than 67% of Hub voting power confirmed installation before the September 23 restart, with blocks resuming at 12:00 UTC.

Cosmos Labs confirmed that the patched binary was tested against a fork of mainnet state and distributed with a checksum. Its source code was initially withheld due to a coordinated disclosure embargo on underlying security fixes, with publication expected after the embargo lifted on September 25.

Governance Vote Required for Release

Six validators—Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu—serve as multisig signers for the recovery wallet. Any four signatures can authorize a transaction, but the signers have stated they will not release funds without an approved Cosmos Hub governance proposal. Cosmos Labs said it holds no key to the wallet.

This creates two separate forms of control: validators changed Hub state during the halt to prevent the attacker from moving the balance, but the custody arrangement now requires a public governance mandate before determining which claimants should receive the recovered ATOM.

Distribution Plan Still in Development

As of September 26, no passed Hub governance proposal authorizing the recovery multisig transfer was visible on the governance list. Proposal 1056, titled "ATOM Refund & Justice Bounty," was still in voting but did not authorize the Neutron response team's distribution plan.

Neutron contributors and affected protocols were preparing evidence of stolen amounts and recovery destinations. The response team was expected to bring a Hub proposal in the following week. Cosmos Labs noted that Neutron had relaunched with mitigations by September 25.

Scope of Recovery Uncertain

The emergency patch captured only ATOM present in one attacker-linked address at the moment of the halt. Approximately 500,000 ATOM had already been swapped through THORChain before the halt, while other stolen assets reached networks beyond the Hub. Another 168,990.9 ATOM arrived at the attacker address after the patch executed—a THORChain refund that arrived just after the restart. This later deposit was subsequently moved to Osmosis and sold.

Cosmos Labs said the patch could not automatically capture funds arriving after the one-time transfer without requiring different code and a longer network halt. The Neutron-side recovery plan must still establish individual claim amounts and distribution addresses before Hub governance can authorize the multisig to act.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.