Cosmos Hub validators used an emergency software upgrade after the Neutron governance attack on September 22 to move 1,227,121.37 ATOM linked to the attacker into a multisignature wallet. The funds have not been returned. The wallet’s six signers say a Cosmos Hub governance proposal must first authorize the transfer before they will release the assets. The intervention stopped some of the affected funds from moving further, but compensation for users and protocols, as well as the allocation process, remains unresolved.
Validators Move the ATOM Through a Software Upgrade
Neutron’s maintenance team said the attacker used a governance proposal on September 22 to obtain administrative control over contracts used by Astroport and other protocols. The attacker then moved part of the assets to other networks, including about 1.73 million ATOM sent to Cosmos Hub. The Hub was not itself attacked, but it became one of the networks where some of the assets could be intercepted.
As the attacker exchanged and bridged ATOM, Hub validators halted the chain at block height 33,086,740 and agreed to restart it with Gaia software version 28.3.0. The patch performed a one-time state change in the first block after the restart, transferring 1,227,121.37 ATOM from an address linked to the attacker into a recovery multisig wallet before normal transactions resumed. A September 24 update from the Cosmos Hub maintenance team said the patch targeted only one source account and did not alter other users’ balances or delegated stakes.
The action was a coordinated validator software upgrade, not compensation approved through an on-chain governance vote. Cosmos Labs said validators received written details before the software was built and distributed, including the sending and receiving addresses, the six signers and the scope of the patch. Before the September 23 restart, validators representing more than 67% of the Hub’s voting power had confirmed installation. The chain resumed at 12:00 UTC, and the asset transfer took effect at about 12:06 UTC.
The maintenance team said the patch had been tested on a fork of mainnet state and distributed with a checksum. Because a security fix in the underlying Gaia v28.2.0 release was still subject to a coordinated disclosure embargo, the source-code differences were not initially published. Cosmos Labs said on September 25 that it expected to release the differences after the embargo ended. That was the disclosure plan stated at the time and does not establish that the material was later published.
Signers Seek Formal Hub Authorization
Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu are the six validators listed as signers of the recovery multisig wallet. The wallet technically requires at least four of the six signatures to execute a transaction. However, the signers said they would use that authority only after a Cosmos Hub governance proposal passed and authorized the transfer. Cosmos Labs said it does not hold the wallet’s keys.
The distinction separates intercepting the assets from deciding who should be compensated. During the halt, validators altered the Hub’s state to prevent the attacker from moving balances that were already on the network. The multisig signers are now seeking a public governance process to determine where the funds should go. The emergency patch did not identify all valid claimants or approve a timetable for distribution.
Neutron is expected to prepare the next stage of the process. Cosmos Labs said that, as of September 25, Neutron had taken mitigation measures and resumed operations. Participants and affected protocols, including Astroport and Drop, were still assembling evidence of losses and distribution plans. The response team expected at the time to submit or support a Hub proposal during the following week. Whether Neutron governance would also need to vote separately was left to that network.
As of 15:40 UTC on September 26, no post-incident proposal visible in the Cosmos Hub governance list had passed and authorized the recovery multisig to distribute the funds. Proposal 1057 concerned restoring the Realio IBC light client. Proposal 1056, titled “ATOM Refund & Justice Bounty,” was still being voted on and had a different refund and bounty structure; it did not authorize the Neutron response team to distribute assets from the multisig wallet. The governance authorization requested by the signers therefore remained outstanding at that time.
168,990.9 ATOM Arrived After the Patch
The funds moved into the multisig represented only the ATOM remaining in one attacker-linked address when the chain was halted. They did not reverse the entire Neutron attack. Cosmos Labs said about 500,000 ATOM had already been exchanged through THORChain before the halt, while other stolen assets had moved to networks outside the Hub. The disclosures did not establish the amount each affected account could ultimately claim, nor did they promise full reimbursement.
A further 168,990.9 ATOM illustrates the patch’s timing limit. A pending THORChain refund reached the attacker’s address shortly after the chain resumed, after the one-time transfer had already executed. Cosmos Labs said validators knew the refund could arrive, but incorporating it would have required new code and a longer halt because the tested patch would have needed to be changed. The ATOM was subsequently moved to Osmosis and sold. Since the patch ran only during the restart, it could not automatically recover assets that arrived later.
Neutron must still verify the losses, eligible claimants and allocation plan before a Hub governance proposal can provide the public authorization requested by the multisig signers. Until those steps are completed, the approximately 1.227 million ATOM already moved to the wallet remains in custody, with the final recipients still undecided.