Cosmos Hub validators lock 1.23 million stolen ATOM pending governance vote
Cosmos Hub validators moved fast to trap a portion of ATOM stolen in a Sept. 22 governance attack on Neutron, but locking the tokens up did not settle who gets them back. Six named validators now hold the recovered funds in a multisig and say they will not move them until Hub token holders pass a separate governance proposal authorizing a distribution.
- Hub validators intercepted 1,227,121.37 ATOM of the roughly 1.73 million ATOM the attacker moved from Neutron.
- Validators representing more than 67% of Hub voting power installed the emergency patch before the Sept. 23 restart.
- A separate 168,990.9 ATOM slipped through after the restart via a pending THORChain refund and was sold on Osmosis.
- 1.23M ATOM secured by Hub validators against 1.73M ATOM stolen from Neutron
- 67% of Hub voting power backed the patch ahead of the Sept. 23 restart
- 500K ATOM already swapped through THORChain before validators halted the chain
- 6 named validators hold multisig keys, with four signatures needed to move funds
The attack began on Neutron on Sept. 22, when a governance proposal handed the attacker administrative control over contracts used by Astroport and other protocols, according to a CryptoSlate report. The attacker began swapping and bridging the stolen assets across chains, sending roughly 1.73 million ATOM to the Cosmos Hub. The Hub itself was not exploited; it simply became a chain where part of the stolen balance could still be caught before it moved further.
Validators halted the chain and rewrote one balance to trap the ATOM
As the attacker moved funds, Hub validators halted the network at block height 33,086,740 and agreed to restart on a patched build of the Gaia software, version 28.3.0. At the first block after the halt, the patch executed a one-time state change moving 1,227,121.37 ATOM out of the attacker-linked Hub address and into a recovery multisig, before ordinary transactions resumed.
The scope was narrow by design. According to the Hub’s Sept. 24 update, the binary touched only that single source account and left every other user balance and delegation untouched.
Validators controlling more than 67% of Hub voting power had confirmed installation of the patch before the Sept. 23 restart, according to Cosmos Labs. Blocks resumed at 12:00 UTC and the recovery transfer executed roughly six minutes later, at about 12:06 UTC. The underlying code diff was withheld at the time because publishing it would have exposed security fixes in the prior v28.2.0 release still under a coordinated disclosure embargo; Cosmos Labs said it expected to release the diff once that embargo lifted.
Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu hold the keys but not the mandate
The recovery multisig sits with six named signers: Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu. Any four of the six can technically authorize a transaction, but the signers have said they will not use that authority until a Hub signaling proposal formally directs where the funds should go. Cosmos Labs said it holds no key to the wallet itself, separating the emergency technical response from the eventual decision over recipients.
A balance check against the recovery address at 15:40 UTC on Sept. 26 showed 1,227,121.374688 ATOM still sitting untouched in the multisig.
Not all of the stolen ATOM was captured. Cosmos Labs said roughly 500,000 ATOM had already been swapped through THORChain before the halt took effect, and other stolen assets reached networks beyond the Hub entirely. A further 168,990.9 ATOM arrived at the attacker’s Hub address just after the restart, through a pending THORChain refund that the one-time patch could not retroactively sweep up; that batch was moved to Osmosis and sold.
Proposal 1056 is in voting but does not authorize this multisig
A check of the Hub’s governance queue at the same Sept. 26 timestamp found no passed mandate covering the recovery multisig among recent entries, according to the on-chain proposal list. The most recent item, Proposal 1057, concerned recovery of a Realio IBC light client and is unrelated. Proposal 1056, titled “ATOM Refund & Justice Bounty,” was still open for voting but sought a different refund and bounty structure and does not authorize the Neutron response team’s planned distribution from this specific wallet.
The governance requirement the six signers have described therefore remains unmet.
Cosmos Labs said Neutron had relaunched with mitigations in place by Friday (September 25), and that contributors along with affected protocols, including Astroport and Drop, were assembling evidence of losses to support a distribution plan. The response team was expected to bring or back a Hub proposal in the following week, according to Cosmos Labs’ Sept. 25 account. Whether Neutron’s own governance also holds a vote is a decision left to that network, the Hub account said.
The BlockWest read. The gap here is not technical but institutional: validators proved they can freeze a stolen balance within hours, yet six private signers are refusing to disburse it without an on-chain mandate, effectively making governance the real custodian of recovered funds. For any protocol treasury or affiliated fund holding ATOM, the practical takeaway is that emergency chain interventions buy time but do not substitute for the slower work of building consensus on who gets paid.
The open question is whether the Neutron response team’s promised proposal, expected sometime in the week following Sept. 25, will name specific claimants and a distribution schedule the six signers accept as their required mandate, or whether Proposal 1056’s separate refund and bounty framework complicates that vote before it reaches the floor.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
