The Cosmos Hub resumed block production on Wednesday morning after its validators kept the network halted for nearly 25 hours — an emergency stop triggered not by a bug on the Hub itself, but by a governance takeover on Neutron that drained an estimated $9.4 million from application contracts and left stolen ATOM sitting on the Hub.

In the first block committed after the restart, 1,227,121 ATOM — about $2.1 million — moved out of the wallet holding the attack proceeds, according to on-chain records cited by Unchained. The transfer appears in the block's events without a transaction signed by the wallet's owner and sent the tokens to a newly created address. The Cosmos Hub account has not said who controls the receiving address.

The episode is the most consequential governance-layer incident in the Cosmos ecosystem this year, and it restarted a debate about what chain-level governance should be allowed to do to applications built on top of it.

How a $20,000 Proposal Became a $9.4 Million Exploit

Neutron proposal 9, titled "AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration," was framed as an experiment in which "autonomous AI agents will take operational control of a live testnet." It traveled Neutron's expedited governance track, which permits a three-day vote, and passed with roughly 82% of votes cast in favor when voting closed at 10:24 p.m. ET on Monday, per the on-chain record.

The proposal's summary concealed its effect: it carried 11 messages that transferred administrative control of Neutron contracts to the proposer's own address. Ten of those contracts belonged to the decentralized exchange Astroport and the liquid staking protocol Drop, according to an on-chain analysis published Tuesday by the analyst Rarma.

The vote itself appears to have been bought rather than earned. Rarma found that the account carrying most of the yes votes acquired about 31.6 million NTRN for 20,199 USDC — roughly $20,000 — and staked it less than 12 minutes before voting closed, locking in just enough voting power at the final tally. The vote "overrode two protocols' own governance, on contracts the chain did not own," Rarma wrote.

Execution followed within half an hour. The attacker replaced the code of 10 of the 11 contracts and emptied them, taking tokens Rarma valued at about $9.4 million. Roughly $1.96 million of that sat on chains that were still running at the time of the analysis. Protos, which put initial losses at $9.5 million, and KuCoin's news desk corroborated the figure and the Astroport–Drop contract exposure.

Two Chains Halt

Neutron stopped producing blocks at 3:43 a.m. ET on Tuesday and remained frozen at publication time, with former contributor Spaydh stating the chain "was halted to prevent further harm." Astroport told users to "withdraw your liquidity from Astroport on all chains until further notice" — a protocol-level warning that extends beyond Neutron itself.

The Cosmos Hub followed on Tuesday. Validators halted the network "to mitigate ATOM losses from a governance exploit on Neutron," stressing that the Hub itself was not affected. In its restart notice, the Cosmos Hub account said the Hub "was not exploited and no funds were impacted apart from the assets moved from Neutron."

The restart block's forced transfer of 1.23 million ATOM is the operationally significant detail: it demonstrates a validator-coordinated ability to move assets out of a specific wallet without the owner's signature — a capability the community invoked here against an attacker, but one whose precedent is already being debated. The Cosmos Hub account said validators were preparing a network update "intended to address the stolen ATOM currently held on the Hub."

The attacker's options narrowed further in the minutes after the restart. A THORChain vault that had received two of the attacker's earlier swaps returned 168,991 ATOM — the unfilled portion of a 200,000-ATOM swap submitted before the halt — and a subsequent attempt by the attacker to send 500,000 ATOM to Osmosis failed for insufficient funds.

No attacker attribution has been established, and the governance records alone do not identify who controlled the proposing and voting accounts.

The Governance Perimeter Problem

The incident's anatomy is what security teams will study. Nothing was exploited in Astroport's or Drop's own contracts, and no private key outside the attacker's control was compromised at the application layer. The vulnerability was permissioning: Neutron's chain governance held administrative authority over contracts it did not own, and that authority was purchasable for the cost of a stake large enough to swing an expedited vote — about $20,000 plus the proposal deposit.

Neutron entered a long-term maintenance phase in June, which raises the further question of who remained watching an expedited governance track with live admin-transfer messages attached. The episode is the second chain-level halt in the Cosmos ecosystem in two months, after Cronos stopped its blockchain in August following an estimated $75 million exploit at the lending protocol Tectonic.

For protocols deployed on general-purpose chains, the practical lesson is to treat chain governance as a live attack surface: administrative control of production contracts should not be assignable by a third party's token vote, however quickly that vote can be convened. For validators, the episode demonstrated both the effectiveness of a coordinated emergency halt and the governance questions that follow when a chain's first post-restart block confiscates a wallet.

TrustGrade tracks governance configurations and the security posture of protocols across major ecosystems. Verified trust data: trustgrade.ai.