Neutron DAO reassigns 11 contract controls as $9.3M vanishes from DeFi protocols
Neutron’s DAO voted to reassign administrator controls across 11 smart contracts on the same day $9.3 million vanished from two DeFi protocols, exposing the governance risk that network-level decisions can override application-level security. For institutional investors assessing custody and DeFi exposure on modular chains, this highlights how protocol governance, not just application audits, determines control over user funds.
- Neutron DAO passed proposal #9 on September 22 with 11 “Update Admin” actions reassigning contract controls across the network.
- SlowMist recorded $4.9 million in losses at Astroport and $4.4 million at Drop on the same date, totaling $9.3 million.
- The proposal demonstrates network governance can change administrator authority over applications users interact with as independent services.
- 11 Administrator updates executed through single governance proposal on Neutron DAO
- $9.3M Combined estimated losses at Astroport and Drop on proposal passage date
- ~20% Approximate share of affected assets extracted beyond network containment by time of reporting
Neutron’s DAO approved a governance proposal titled “AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration” on Tuesday, September 22 that reassigned administrative control of 11 smart contracts across the network. On the same day, security tracker SlowMist recorded an estimated $9.3 million in combined losses: $4.9 million at decentralized exchange Astroport and $4.4 million at liquid staking protocol Drop, according to reporting by CryptoSlate. The timing and scale of the administrator changes occurring simultaneous with major fund loss exposes a structural risk in how modular blockchain networks distribute authority between governance layers and application developers.
Neutron DAO votes to centralize administrator authority across 11 contracts
Neutron’s governance documentation designates the DAO as the network’s highest governing authority, with explicit power to execute messages across the protocol. The “Update Admin” action identified in the proposal allows the network-level governance process to change which address controls a contract’s administrator functions, regardless of how users perceive the application, Astroport and Drop operate as independent DeFi services to end users, but their core control logic ultimately routes through Neutron governance decisions. The proposal’s 11 administrator updates represent the scope of contracts whose control was reassigned in a single governance action.
This structure creates a governance risk often overlooked in application-level security assessments.
An audited DeFi protocol with proper code review and operational procedures can still face control changes imposed at the network layer, effectively shifting authority from the application’s developers to the blockchain’s DAO. Institutional investors accustomed to evaluating protocols through audit reports and operational track records may not factor in how a single network governance vote can alter the administrative authority chain.
SlowMist records $9.3 million in combined losses as network containment limits extraction
SlowMist’s incident tracker named Astroport and Drop in its September 22 records following the DAO proposal. The $9.3 million combined estimate reflects reported fund movements at both protocols, though the exact recovery outlook remains uncertain. Security reporting indicates that a network halt contained most initially affected assets, preventing immediate extraction of the full amount.
By the time Protos reported on the incident on September 23, the attacker had extracted approximately one-fifth of the initially affected assets beyond the network’s containment boundaries. The difference between the total loss estimate and the extracted share highlights the gap between reported incident value and actual recoverable funds.
A network halt can freeze assets without returning them to users, leaving the final loss figure dependent on which funds remain contained, which have been restored, and which have exited the network entirely, three distinct outcomes with very different implications for affected users and the protocols involved.
Recovery path hinges on asset containment and protocol restoration timeline
The unresolved question for affected users centers on how much of the reported $9.3 million can actually be returned. The journey from initial loss to user recovery requires multiple steps: withdrawal from an application, potential movement between networks, containment during network halts, and eventual restoration to user accounts.
Each step introduces the possibility of permanent loss or successful recovery.
Institutional custodians and DeFi exposure managers will need to monitor both the technical recovery efforts and governance decisions around how Neutron DAO and the affected protocols coordinate restoration.
The episode underscores that protocol security depends not only on application-level audits but also on the governance layer’s ability to act decisively when administrator authority intersects with crisis response.
The CCS read. We see the governance structure working as designed: the DAO executed administrator changes it had authority to make. The institutional risk is not that Neutron governance acted, but that investors in DeFi applications on modular chains must now assess governance risk as an irreducible part of protocol exposure, equivalent in some cases to application risk itself.
Watch for Neutron DAO’s next governance action: whether it clarifies the relationship between network-level administrator authority and application safeguards, and whether the community votes on restrictions on future administrator reassignments. The protocols’ ability to restore and retain user confidence will also depend on how much of the contained $9.3 million flows back to affected users in the coming weeks.