Neutron Governance Attack: Cosmos Hub Response and Recovery Update

Overview

On September 22, 2026, a governance attack on Neutron drained liquidity from Astroport and other protocols on that network. Before Neutron halted, the attacker bridged the stolen assets to a variety of chains, and a portion of the stolen assets, roughly 1.7M ATOM, were bridged to the Cosmos Hub. The Cosmos Hub itself was not exploited. No Hub user funds were affected.

Hub validators halted the network at height 33,086,740 to stop the remaining ATOM from leaving and being lost. Roughly 24 hours later, they restarted on a patched Gaia binary (v28.3.0) that applied a single, one-time change at the halt height, moving 1,227,121 ATOM from the attacker’s address into a 4-of-6 multisig created to aid recovery of the funds and held by community validators (cosmos1z8pq5cn7tdrwwzlwm0e44fgq07e43ner6vph64).

Block production resumed at 12:00 UTC on September 23.

This post covers the Hub side only: what funds arrived at the Hub, what validators did, where the funds are, and how next steps will be coordinated. The complete post-mortem of the attack is being prepared by Neutron’s maintainers, to be shared early next week.

Cosmos Labs is publishing this update in its role as a maintainer of the Hub software, and as the team that coordinated communication on behalf of validators through the halt and restart, so that validators, node operators, and the wider Hub community have a single account of what happened and where things stand.


Response at a glance

  • Tuesday, September 22, 2026: Neutron notified Hub validators and Cosmos Labs at ~09:53 UTC. The Hub was halted by ~11:18 UTC.
  • Validators had the full written plan by ~15:20 UTC, about 3.5 hours after the halt and before any code shipped: the exact change, the source and destination addresses, the six signers for the multisig, and the one-account scope.
  • Patched binary built, e2e- and fork-tested, and distributed to validators by ~19:50 UTC, about 7.5 hours after the halt.
  • Wednesday, September 23, 2026: Validators representing more than 67% of voting power confirmed the patch installed by ~00:50 UTC, about 5 hours after distribution, including Coinbase, Kraken, and other custodians.
  • Restart at 12:00 UTC on September 23; migration applied at 12:06 UTC with a supermajority secured upon restart and 174/180 validators online by end of day.
  • The attacker’s address has been flagged to more than 30 exchanges, bridges, and custodians, before and after the restart. We are coordinating with the Neutron recovery team to gather any further details on the attacker that can be shared with their security teams.

Timeline (UTC)

Time Height Event
Sep 22, ~02:25–07:44 Neutron 61,635,573 Proposal executed on Neutron, acquiring admin control over contracts of Astroport and other protocols; malicious code was added, and funds were drained; Neutron validators halted the network. Attacker bridges part of the funds in ATOM to the Hub and begins swapping through THORChain.
Sep 22, ~09:50 — Neutron contributors and community members alert Hub validators and Cosmos Labs. Joint coordination channel opens (Neutron, Cosmos Labs, Cosmos Labs Korea, validators).
Sep 22, ~11:00–11:18 33,086,740 Validators representing over a third of voting power stop their nodes. The Hub halts. Public notice from cosmoshub on X.
Sep 22, ~15:20 halted Validators briefed in writing on the recovery approach: a one-time change at the halt height moving the attacker’s remaining ATOM to a validator-held multisig, with source and destination addresses, the six multisig members, one account touched, and testnet verification before mainnet. Validators asked to stay halted and wait for the binary. At validators’ request and as maintainers, Cosmos Labs begins the patch. First notices go to exchanges, bridges, and node operators. ZeroShadow supports tracing; Neutron contributors share their own trace.
Sep 22, ~19:00 halted Multisig confirmed: Nansen, Keplr, Enigma, Silknodes, Kiln, Polkachu, threshold 4 of 6. Address derived independently by signers and verified with a test transaction on the provider testnet.
Sep 22, ~19:50 halted v28.3.0 built, tested, and distributed with SHA-256 checksum. Instructions: install, do not start, confirm readiness.
Sep 22, ~22:30–23:30 halted A pending THORChain refund to the attacker address is identified (see below). With a distribution of tested binary already ongoing, and a different scope of code required to address this, validators continued with the existing binary and prioritized acting on the main pool of recoverable funds over the risk of a longer halt and code modification. These funds were considered lost.
Sep 23, ~00:30 halted >67% of voting power confirmed on v28.3.0. Restart set for 12:00 UTC and announced to validators, exchanges, node operators.
Sep 23, 12:00–12:06 33,086,741 Coordinated restart successful. Change applied: 1,227,121.37 ATOM moved from cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n to the multisig cosmos1z8pq5cn7tdrwwzlwm0e44fgq07e43ner6vph64. Blocks resume.
Sep 23, ~12:10 33,086,742+ THORChain refund of 168,990.9 ATOM arrives at the attacker address and is moved to Osmosis and sold.
Sep 23 — Exchanges told the Hub is stable and deposits/withdrawals can resume; attacker address blocks confirmed by several.

Total halt: approximately 24.5 hours.


Scope of the response

What reached the Hub and what was recovered

  • ~1.73M ATOM reached the Hub.
  • Roughly 500,000 ATOM was swapped through THORChain to ETH before the halt. Not recoverable. 168,990.9 ATOM was refunded to the attacker by THORChain after the restart and moved out before it could be secured.
  • 1,227,121 ATOM remained in the attacker’s Hub address at the halt height and was moved to the multisig on restart.

The multisig holds everything that was recoverable on the Hub. It is not the full loss from the attack, which included other assets on other chains.

What this response could and could not do

Hub validators can only act on Hub state, and Cosmos Labs can only act on a mandate from validators. This response was possible because a large share of the stolen ATOM was sitting in one address on the Hub at the moment validators halted. Nothing here touches assets that went elsewhere: the ATOM swapped through THORChain, DYDX on dYdX, USDC on Noble, funds on Osmosis, Axelar or EVM chains, or anything still on Neutron.

Those are for the respective networks and the teams supporting Neutron’s response, who are coordinating their own recovery. The Hub’s role ends at the multisig.

Validators’ reasoning behind the halt

The ATOM extracted by the attacker had been sent from Neutron to the Hub, where the attacker could keep bridging and swapping it, increasing losses. Neutron’s halt could not stop that.

Stopping the outflow required stopping the Hub, and recovering the ATOM required validators to coordinate an update, which required a halt and a coordinated restart. Validators chose to halt in support of Neutron and affected protocols.

Recovery approach: one-time transfer to a validator multisig

A validator multisig was proposed and decided as the best and quickest way to safely protect the funds without prescribing a destination until the networks could be restored and the affected networks, protocols, and involved parties could be consulted normally.

At the time, Neutron was halted, and the attacker still held voting power there, so the funds could not go back on restart without being at risk again. Furthermore, leaving them in place in the Hub meant the attacker would be able to extract them and increase overall losses.

Validators agreed to move the ATOM at the halt height, before any transactions are processed, into a 4-of-6 multisig of established community validators. Several validators were approached about signing. Some agreed; others supported the approach but declined to hold a key. Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu are the six who agreed and responded promptly.

The multisig signers view their role as a technical function only: the multisig exists solely to return the exfiltrated funds to affected accounts. The signers will not stake, lend, trade, or otherwise deal with the assets, and will act only to execute legitimate returns as soon as that is possible, and will hold the funds pending such a mandate. The signers have stated that such a mandate exists only when clearly expressed through Cosmos Hub governance, specifically, the passage of a Cosmos Hub governance proposal authorizing the transfer. Absent a passed signaling proposal, no transfer will be executed.

The Neutron recovery team has agreed with the signers’ position. They expect to submit the Hub governance proposal in the coming week and have said their priority is that each step is handled carefully and transparently before any funds move.

How the binary was built and adopted

The patch was written as a single, removable commit on top of v28.2.0, ran end-to-end and fork tests against mainnet state, and shipped the binary within 7.5 hours of the halt. The multisig address was hardcoded only after four of the six signers had derived it independently and executed a test transaction on the provider testnet.

It was distributed as a binary with a published checksum, because it is built on v28.2.0, whose security fixes are still under a coordinated disclosure embargo; publishing the v28.3.0 source would expose them. The diff will be published once that embargo lifts, expected in the coming week.

Validators were told in writing, before any code was distributed, exactly what the binary would do: which address it moves funds from, which multisig it moves them to, and who the signers are.

Each validator chose whether to install it. 67% of voting power was confirmed swiftly under the new update, allowing for a safe restart.

Validators installed without restarting, confirmed, and waited for the coordinated restart hour. The chain restarted only after validators representing more than two-thirds of voting power had done so. To date, 96% of validators agreed to the update and successfully upgraded.

The THORChain refund

Referencing the 168,990.9 ATOM that was refunded to the attacker by THORChain after the restart and moved out before it could be secured:

By the time the possibility of a refund from THORChain became known, the Hub had been halted for many hours, and the v28.3.0 binary had already been distributed and installed by over half of all validators, including major custodians and exchanges. Reverting to a separate binary would have meant significant technical risk to the Cosmos Hub at worst, and a prolonged chain halt at best.

Validators had agreed to a one-time move of the funds present at the halt height. Blocking future transactions from an address, or sweeping whatever arrives later, was outside the scope of the actions that were authorized or deemed safe by the validators at that critical stage in the upgrade process. Cosmos Labs did not add it on its own initiative. The patch as written performs a one-time transfer.

The refund of 168,990.9 ATOM arrived after the restart and was moved out. That tranche is treated as lost.


Current state

  • Cosmos Hub operating normally on v28.3.0.
  • 1,227,121 ATOM held in the 4-of-6 recovery multisig (Nansen, Keplr, Enigma, Silknodes, Kiln, Polkachu). Funds move only on a mandate.
  • Attacker address and related addresses shared with exchanges and bridges. Several have confirmed blocks.
  • ZeroShadow has independently verified the trace.
  • Neutron has relaunched with mitigations in place.
  • Neutron contributors will publish their own post-mortem early next week.

Next steps

The multisig holds the funds while the Neutron side completes its recovery plan and network restart work. This section describes how the coordination between the parties looks from our side; it is not a plan Cosmos Labs is setting. Based on those conversations, the following need to be in place before the funds move:

  1. Neutron restart. Neutron is relaunching with mitigations in place, restored contract admins, and its own recovery multisig. Until the relaunch is complete and stable, there is no destination on Neutron for the funds. This is done as of today; Neutron is back online with new mitigations in place, thanks to the effort of ecosystem contributors and maintainers.
  2. Recovery plan from the Neutron side. The teams contributing to the Neutron response are preparing it, including evidence of what was taken, where the funds should go, and how.
  3. Multisig mandate. The expected route is a Cosmos Hub governance proposal brought by the Neutron response team, or with their backing, that presents the recovery plan and authorises the transfer from the Hub validator multisig. Whether Neutron governance also weighs in is for the Neutron side to decide.

Coordination happens in public. All involved teams are connected: the Neutron response team (including Solva, Astroport, Drop, and other affected protocols), the multisig signers, and the validators who took part in the halt and restart share channels established during the incident.

The Neutron response party will begin working on proposals across the different involved networks shortly, expecting to share updates by early next week. The proposals will be drafted by the affected parties; neither Cosmos Labs nor multisig validators will be involved in their content.

We encourage the involved parties to use this thread to publish updates and the recovery plan for the Hub community ahead of any proposal.

We at Cosmos Labs remain available to the signers, the Neutron-ecosystem teams, and the Hub community for coordination, technical questions, help with proposal mechanics if asked, and updates to this thread.


Cosmos Labs’ role in this response was as maintainers of the Hub software and coordinators of communication. Cosmos Labs put the upgrade approach to validators in writing and, once validators had agreed to it, built, tested, and distributed the binary with Cosmos Labs Korea and ran outreach to validators, exchanges, and node operators.

Nothing in this response went ahead without the agreement of validators representing a supermajority of voting power. Cosmos Labs holds no key to the multisig and has no control over the funds. What happens to them next is for the affected protocols and the signers to work out, through the processes described.


Acknowledgements

  • Cosmos Hub validators, for halting on short notice, installing the patch across time zones overnight, and restarting on schedule.
  • Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu, for agreeing to act as multisig signers on the day of the incident.
  • Hadron Labs, for the initial alert, the trace, and continuous coordination.
  • Solva, for leading the Neutron relaunch and post-mortem.
  • Astroport, Drop, and the other affected protocols, and the Neutron community members working on recovery.
  • Rarma, for the original trace of funds, identifying the pending THORChain refund and keeping the community informed of the movement of funds on-chain.
  • ZeroShadow, for independent verification of the trace.
1 Like