Cosmos Hub Captures 1.23M Stolen ATOM With Emergency Patch as Recovery Work Continues
AI مارکیٹ کا خلاصہ
Cosmos Hub validators intercepted 1.227M stolen ATOM via an emergency Gaia 28.3.0 patch and a one-time state transfer to a recovery multisig after a Neutron governance attack routed funds onto the Hub. While this reduces immediate circulating overhang, distribution and claimant verification remain unresolved and require governance authorization. A portion of ATOM was already swapped via THORChain and additional refunds escaped post-restart, sustaining residual uncertainty.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ATOM/USDT+2.01%
AI تجزیاتی سمجھ · ATOM/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Cosmos Hub validators have recovered 1,227,121.37 ATOM by deploying an emergency software patch, after an attacker routed roughly 1.73 million stolen ATOM from Neutron to the Hub during a governance attack on Sept. 22.
The Hub itself was not breached. Instead, it became the point where part of the stolen balance could be intercepted. Validators halted the chain at height 33,086,740 and restarted it on Gaia v28.3.0. The patch executed a one-time state change that moved ATOM from an attacker-linked address into a recovery multisig, taking effect around 12:06 UTC on Sept. 23. Validators representing more than 67% of Hub voting power confirmed installation before the restart, and block production resumed at 12:00 UTC.
As of 15:40 UTC on Sept. 26, the recovery address held 1,227,121.374688 ATOM. The patch was limited to a single source account and did not alter other user balances or delegations.
The recovery multisig has six signers: Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu. The wallet requires four signatures to execute a transaction. The signers said they will not release funds without an approved Cosmos Hub governance proposal authorizing a legitimate transfer. Cosmos Labs said it does not control any keys for the wallet.
Cosmos Labs also said the emergency patch did not determine every valid claimant or approve any distribution schedule. The Neutron response team was preparing evidence and a distribution plan, while contributors and affected protocols, including Astroport and Drop, were compiling proof of what was taken and how recovered assets should be allocated. The response team was expected to bring or support a Hub proposal the following week.
At 15:40 UTC on Sept. 26, the Hub proposal list showed no passed mandate governing distributions from the recovery multisig. Proposal 1056, "ATOM Refund & Justice Bounty," remained in voting and did not authorize the Neutron response team to distribute funds from this multisig.
Cosmos Labs estimated about 500,000 ATOM had already been swapped via THORChain before the chain halt, and other stolen assets had moved to networks beyond the Hub. The recovery action does not determine the final claim size for each affected account and does not guarantee full reimbursement.
A further 168,990.9 ATOM reached the attacker address via a pending THORChain refund shortly after the restart. Validators were aware the refund could arrive; capturing it would have required different code and a longer halt. The refunded ATOM was then moved to Osmosis and sold.
The Neutron recovery plan still needs to establish who is owed what, and where recovered funds should ultimately be sent.