Cosmos Hub validators freeze 1.23 million stolen ATOM pending governance approval
Cosmos Hub validators have locked 1,227,121.37 ATOM stolen in a Sept. 22 (Monday) governance attack on Neutron, but the six-signer multisig holding those tokens says it will not release them until Hub token holders pass a separate authorization vote. The episode shows that halting a blockchain to freeze stolen funds and deciding who gets them back are two different processes, with the second now stuck in an ongoing governance queue.
- Hub validators used a one-time patch to move 1,227,121.37 ATOM from an attacker-linked address to a recovery multisig.
- More than 67% of Hub voting power confirmed the patch before the Sept. 23 (Tuesday) restart, which took effect at roughly 12:06 UTC.
- A separate 168,990.9 ATOM refund reached the attacker’s address just after the restart and was later sold on Osmosis.
- 1.23M ATOM frozen in the recovery multisig versus 1.73M taken
- 67% Hub validator power confirming the patch before restart
- 169K ATOM that slipped past the patch and was sold
An attacker exploited a Neutron governance proposal on Monday (Sept. 22) to seize administrative control of contracts used by Astroport and other protocols, then moved roughly 1.73 million stolen ATOM onto the Cosmos Hub. The Hub itself was never compromised; it simply became the network where part of the stolen balance was still reachable. Hub validators halted the chain at height 33,086,740 and, according to a Sept. 25 (Thursday) account from Cosmos Labs, restarted on a patched build of Gaia, version 28.3.0.
Validators Move 1.23 Million ATOM Before Restart, Not After a Vote
The patch made a single state change at the first block after the halt, shifting 1,227,121.37 ATOM from the attacker-linked address to a recovery wallet before ordinary transactions resumed. A Sept. 24 (Wednesday) update from Hub maintainers says the binary touched only that one source account and left every other user’s balance and delegation untouched. Validators representing more than 67% of Hub voting power had confirmed installation before the Sept. 23 (Tuesday) restart.
Blocks resumed at 12:00 UTC and the transfer executed roughly six minutes later. Cosmos Labs said the binary’s source diff was withheld at the time because publishing it would have exposed security fixes still under a coordinated disclosure embargo tied to the earlier v28.2.0 release.
A Hub balance query run at 15:40 UTC on Friday (Sept. 26) confirmed the multisig still held 1,227,121.374688 ATOM, matching the amount seized during the restart. The six named signers, Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu, need only four of six signatures to move the funds technically. Cosmos Labs says it holds no key to the wallet itself, leaving the decision entirely with the signers and, they say, with Hub governance.
Proposal 1056 Is Still Voting and Does Not Cover This Multisig
The signers have stated one condition before touching the frozen ATOM: a passed Hub signaling proposal authorizing a legitimate transfer. A check of the Hub governance proposal list at the same Sept. 26 (Friday) timestamp found no such mandate among recent entries. The most recent, proposal 1057, dealt with recovering a separate Realio IBC light client, unrelated to the ATOM seizure.
Proposal 1056, titled “ATOM Refund & Justice Bounty,” was still in voting at the time of the check. It seeks a different refund and bounty structure and does not authorize the Neutron response team’s distribution from this specific multisig.
That gap matters for institutional holders exposed to Astroport, Drop and other Neutron protocols hit in the attack: custody of the stolen ATOM does not equal a claims process. Cosmos Labs said Neutron had relaunched with mitigations by Thursday (Sept. 25), and that affected protocols were still preparing evidence of what was taken before bringing a Hub proposal in the following week.
Whether Neutron’s own governance also holds a separate vote is, according to the Hub account, a decision left to that network, not the Hub.
168,990 ATOM Missed the Patch and Was Sold on Osmosis
The recovery effort has a hard boundary: it only captured ATOM sitting in one attacker-linked address at the moment of the halt. A pending THORChain refund of 168,990.9 ATOM reached that same attacker address just after the restart, arriving too late for the one-time patch to sweep it.
Cosmos Labs said validators anticipated the refund might land but that capturing it would have required different code and a longer chain halt, a tradeoff they chose not to make.
That ATOM was moved to Osmosis and sold. Separately, roughly 500,000 ATOM had already been swapped through THORChain before the Hub halt even began, placing it beyond the reach of any Cosmos-side recovery.
The mismatch illustrates a limit institutional custodians and validators are increasingly confronting: a coordinated freeze can stop a snapshot of stolen funds but not a moving attacker. Emergency code applied once at a fixed height cannot automatically catch assets arriving minutes later through a different bridge.
The CCS read. The split between freezing funds and authorizing their release is the real story for institutional participants. A six-signer multisig backed by 67% of validator power moved fast to stop losses, but it deliberately refused to also decide who gets paid, pushing that call to a slower, public vote. That separation of technical custody from distribution authority is a governance model worth watching as more chains face similar exploits.
Cosmos Labs said the Neutron response team expected to bring or back a Hub proposal covering the recovered ATOM in the week following its Sept. 25 update, a proposal that had not yet appeared in the governance queue as of the Sept. 26 check. Until Hub token holders pass that mandate, the 1,227,121.37 ATOM sits secured but unclaimed, with the size of each affected protocol’s entitlement still undetermined.
Original reporting: cryptoslate.com