On September 22, an attacker transferred approximately 1.73 million stolen ATOM from Neutron to the Cosmos Hub during a governance attack. Validators intercepted 1,227,121.37 ATOM through an emergency software patch, though the six multisig signers controlling the funds insist that a separate Hub governance proposal must pass before releasing them to affected users and protocols.
As detailed in a September 25 Cosmos Labs report, this condition distinguishes the emergency measure taken to halt further outflows from the subsequent decision on fund allocation. A balance query at 15:40 UTC on September 26 showed the recovery address holding 1,227,121.374688 ATOM. While the tokens remained in custody, Cosmos Labs noted the Neutron response team was still compiling evidence and a distribution plan to support the return.
How Validators Secured the Stolen ATOM
The attack originated on Neutron on September 22, when a governance proposal granted the attacker administrative control over contracts used by Astroport and other protocols, according to Hub maintainers. The attacker moved stolen assets across networks, including roughly 1.73 million ATOM to the Cosmos Hub. The Hub itself was not compromised; it simply became the location where part of the stolen balance could be intercepted.
As the attacker swapped and bridged ATOM, Hub validators halted the chain at block height 33,086,740. They subsequently agreed to restart using a patched version of Gaia software, v28.3.0. At the first height after the halt, the patch executed a one-time state change, transferring 1,227,121.37 ATOM from the attacker-linked Hub address to a recovery multisig before ordinary transactions resumed. The Hub’s September 24 update confirmed the binary was scoped to that single source account and did not alter other user balances or delegations.
The process was a coordinated validator update, not an on-chain vote authorizing compensation. Cosmos Labs stated that validators received the written source and destination addresses, the list of six signers, and the proposed scope before building and distributing the binary. Validators representing more than 67% of Hub voting power confirmed installation before the September 23 restart. Blocks resumed at 12:00 UTC, and the transfer took effect at approximately 12:06 UTC.
Maintainers said the binary was tested against a fork of mainnet state and distributed with a checksum. The source diff was withheld because publication would expose security fixes in the underlying v28.2.0 release, which remained under a coordinated disclosure embargo. Cosmos Labs expected to publish the diff after the embargo lifted, though this September 25 timetable was not confirmation of a later release.
Custody Does Not Determine Who Receives the Funds
Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu are the six validators named as multisig signers. Any four signatures meet the wallet’s technical threshold for a transaction. The signers have stated a separate condition for using that capability: a passed Cosmos Hub signaling proposal must authorize a legitimate transfer. Cosmos Labs says it holds no key to the wallet.
This creates two distinct forms of control. A supermajority of validators agreed to change Hub state during the halt so the attacker could not move the balance already present. The custody signers now hold the stolen ATOM but say they will wait for a public governance mandate before deciding a destination. The emergency patch did not identify every valid claimant or approve a distribution schedule.
The proposed route begins on Neutron’s side. Cosmos Labs said Neutron had relaunched with mitigations by September 25, while contributors and affected protocols, including Astroport and Drop, were preparing evidence of what was taken and where recovered assets should go. The response team was expected to bring forward a Hub proposal in the following week. Whether Neutron governance also holds a vote is for that network to decide, the Hub account said.
The Hub governance proposal list checked at 15:40 UTC on September 26 showed no passed mandate for the recovery multisig among its visible post-incident entries. The latest proposal, 1057, concerned recovery of a Realio IBC light client. Proposal 1056, titled “ATOM Refund & Justice Bounty,” was still in voting and sought a different refund and bounty; it did not authorize the Neutron response team’s distribution from this multisig. The governance requirement therefore remained prospective at the time of the check.
The Hub transfer covered the ATOM sitting in one attacker-linked address at the time of the halt. It did not reverse the wider Neutron attack. Cosmos Labs said roughly 500,000 ATOM had already been swapped through THORChain before the halt, while other stolen assets reached networks beyond the Hub. The account does not establish the final size of each affected account’s claim or promise full reimbursement.
Why the Patch Could Not Capture Later Funds
Another 168,990.9 ATOM illustrates the patch’s time limit. A pending THORChain refund reached the attacker address just after the restart, after the one-time transfer had executed. Cosmos Labs said validators knew the refund might arrive, but changing the tested binary to capture it would have required different code and a longer halt. The returned ATOM was moved to Osmosis and sold. It was a later arrival at the attacker address, separate from the balance already transferred to the multisig. A rule applied once at the restart could not automatically sweep a later deposit.
The Neutron-side recovery plan must still establish who is owed what and where the funds should go. A Hub proposal backed by that plan would then give the six signers the public mandate they say they require. Until those steps occur, the secured ATOM remains available for recovery, with its recipients unresolved.
Also Read
- SEC staff’s staking-token split spotlights the exit risks behind staked ETH tokens
- Ethereum’s 2030 Roadmap: Scaling Through Parallel Processing and Strengthening Privacy
- Altcoin Momentum Surges as SUI and BCH Leave BTC and ETH Behind
- Collateral Backing Could Give Ethereum Transactions an Instant Feel


