Live Prices
Altcoins

Cosmos Intercepts 1.23 Million Stolen ATOM, Payout Awaits Governance Vote

TheCryptoDesk Editorial · 3m read
Cosmos Intercepts 1.23 Million Stolen ATOM, Payout Awaits Governance Vote

Cosmos Hub validators intercepted 1,227,121.37 ATOM following a Sept. 22 governance exploit on Neutron, but the six multisig signers holding the funds say a separate governance vote must pass before any assets are refunded. The multi-signature wallet held exactly 1,227,121.374688 ATOM as of 15:40 UTC on Sept. 26, awaiting a formal evidence and distribution plan from affected teams.

Key Takeaways

  • 1,227,121.37 ATOM was secured by Cosmos Hub validators after an attacker attempted to move 1.73 million ATOM out of Neutron.
  • Chain operations were halted at height 33,086,740 and restarted using patched Gaia v28.3.0 software backed by over 67% of validator voting power.
  • Custody is managed by a 4-of-6 multisig involving Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu.
  • A late 168,990.9 ATOM refund from THORChain arrived after the restart and escaped to Osmosis where it was sold.

The Emergency Patch and Asset Interception

The attack began on Neutron on Sept. 22, when a rogue governance proposal granted the attacker administrative control over contracts utilized by Astroport and other decentralized protocols. The attacker subsequently funneled roughly 1.73 million ATOM toward the Cosmos Hub. Around 500,000 ATOM had already been swapped through decentralized avenues prior to intervention, similar to previous cross-chain tracing issues seen when THORChain rejected requests to freeze stolen assets.

To prevent further dissipation, Cosmos Hub validators halted block production at height 33,086,740. Validators holding more than 67% of network voting power agreed to restart on patched Gaia v28.3.0 software. At block restart—which resumed at 12:00 UTC on Sept. 23—the software executed a one-time state override at 12:06 UTC that transferred 1,227,121.37 ATOM directly from the attacker's address to a designated recovery multisig.

However, the single-execution patch could not capture funds arriving later. A pending 168,990.9 ATOM refund from THORChain landed in the attacker's Hub account shortly after the chain restarted. Because the patch code had already executed, the attacker successfully transferred those funds to Osmosis and liquidated them.

Governance Vote Required for Asset Distribution

While the tokens are safely secured in custody, the six multisig signers—Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu—have specified that they will not disburse funds without explicit authorization from a passed Cosmos Hub signaling proposal. Four out of six signatures are required to move assets, but Cosmos Labs confirmed it holds no access keys to the wallet.

As of 15:40 UTC on Sept. 26, no approved distribution mandate existed on-chain. Proposal 1056, titled "ATOM Refund & Justice Bounty," was actively in voting but requested a different refund structure, while Proposal 1057 addressed an unrelated recovery of a Realio IBC light client. Response teams from Neutron, Astroport, and Drop are preparing evidence to back a formal distribution proposal.

Why It Matters

This recovery attempt highlights the delicate balance between emergency blockchain interventions and decentralized governance principles. While hard forks and state overrides can successfully freeze stolen assets during active exploits, enforcing a mandatory governance vote before disbursing funds prevents key signers from acting as unilateral arbiters of capital recovery. As inter-blockchain ecosystems expand—and face operational friction similar to broad migrations seen when LayerZero faced a lawsuit and asset migration—establishing structured, vote-driven recovery workflows remains essential for cross-chain security.

Read next