← All stories
🛡️

Cosmos Hub and Neutron: cross-chain governance exploit fallout

Events across Neutron and Cosmos Hub highlighted cross-chain composability risks when a governance attack on Neutron spilled assets onto Cosmos Hub. The attacker bought voting power for roughly 20,199 USDC and used an expedited proposal to reassign administrative rights over 11 smart contracts, allowing malicious migrations that exposed an estimated $9.3–$9.5 million in assets across affected contracts including Astroport and Drop.

Neutron’s rate limits and a rapid halt protected a portion of those funds, but about 1.2–1.23 million ATOM were transferred to a Cosmos Hub address. To prevent further movement, Hub validators coordinated a rare full network halt lasting about 24 hours 48 minutes (reported as 25 hours in some accounts). Upon restart, the first post-upgrade block swept 1,227,121.37 ATOM (roughly 1.23 million ATOM, about $2.2 million) into a recovery address and the bulk of recovered ATOM was placed into a community validator multisig while parties coordinated asset return.

A gap remained: a later THORChain refund of 168,990.9 ATOM arrived at the attacker-linked address after the sweep and was transferred to Osmosis, eventually yielding around 266,841 USDC in sales. Observers noted an earlier attempted 500,000 ATOM transfer that failed for insufficient fees but demonstrated the address could still submit IBC transfers after restart. Neutron contributors prepared a new binary to restore contracts, tighten governance, and move remaining attacker-controlled assets into a validator multisig; a full post‑mortem and coordinated return process were planned once Neutron resumes block production.

This summary is composed by the cFlash AI editor from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources