Cosmos Locks Up 1.23M Stolen ATOM; Refunds Pending Separate Governance Approval

AI مارکیٹ کا خلاصہ
Cosmos Hub validators halted the chain and deployed an emergency patch to seize 1,227,121.37 stolen ATOM into a recovery multisig after a Neutron governance exploit routed ~1.73M ATOM to the Hub. However, the six multisig signers will not release funds without a separate Hub governance mandate and a Neutron-led evidence/distribution plan. Near-term risk centers on governance/process uncertainty and incomplete recovery, with additional ATOM already laundered via THORChain.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ATOM/USDT+1.13%
AI تجزیاتی سمجھ · ATOM/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Cosmos Hub validators have secured 1,227,121.37 ATOM that an attacker routed from Neutron to the Hub during a Sept. 22 governance exploit, but the funds will not be released until a separate Cosmos Hub governance proposal authorizes the payout, according to a Sept. 25 update from Cosmos Labs. A Hub balance query at 15:40 UTC on Sept. 26 showed 1,227,121.374688 ATOM sitting at the recovery address. Cosmos Labs said the tokens remain in custody while Neutron's response team prepares the evidence package and distribution plan needed to support a return to affected users and protocols. How the Hub intercepted the funds The incident began on Neutron on Sept. 22. Hub maintainers said a malicious governance proposal granted the attacker administrative control over contracts used by Astroport and other protocols. The attacker bridged and swapped assets across networks, including about 1.73 million ATOM sent to the Cosmos Hub. Cosmos Hub itself was not exploited. Instead, validators used an emergency process to intercept part of the stolen flow after it reached the Hub. As the attacker was swapping and bridging ATOM, validators halted the chain at height 33,086,740 and coordinated a restart on a patched Gaia release, v28.3.0. At the first block height after the halt, the patch executed a one-time state change: it transferred 1,227,121.37 ATOM from an attacker-linked Hub address to a recovery multisig before normal transactions resumed. A Sept. 24 Hub update said the binary was narrowly scoped to that single source account and did not alter other user balances or delegations. Cosmos Labs said validators were provided in advance with the written source and destination addresses, the list of six multisig signers, and the intended scope before it built and distributed the binary. Validators representing more than 67% of Hub voting power had confirmed installation before the Sept. 23 restart. Blocks resumed at 12:00 UTC, and the transfer took effect around 12:06 UTC. Maintainers said the binary was tested against a fork of mainnet state and shipped with a checksum. The source diff was not published immediately because disclosure would have revealed security fixes in the underlying v28.2.0 release that were still under a coordinated disclosure embargo. Cosmos Labs said it expected to publish the diff after the embargo lifted, reflecting its Sept. 25 disclosure timeline. Custody does not determine who gets paid The recovery wallet is controlled by a multisig whose signers are Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu. Any four signatures meet the wallet's technical threshold to move funds. The signers have added a separate requirement: they say they will not authorize any transfer unless a Cosmos Hub signaling proposal passes to provide a governance mandate. Cosmos Labs said it does not control any key to the wallet. That split creates two layers of decision-making. Validators used a supermajority to modify state during the halt so the attacker could not move the balance already on the Hub. The multisig signers now control the secured ATOM, but say governance must decide where it should go. Cosmos Labs emphasized that the emergency patch did not determine valid claimants or approve a distribution schedule. The proposed path starts on Neutron: Cosmos Labs said Neutron had relaunched with mitigations by Sept. 25, while contributors and impacted protocols including Astroport and Drop were assembling proof of losses and a plan for where recovered assets should be sent. The response team was expected to bring forward a Hub proposal in the following week. As of 15:40 UTC on Sept. 26, the Hub's governance list showed no passed proposal authorizing disbursement from the recovery multisig among visible post-incident entries. Proposal 1057 dealt with recovery of a Realio IBC light client. Proposal 1056, titled "ATOM Refund & Justice Bounty," was still in voting and sought a different refund and bounty structure; it did not authorize distribution from this multisig tied to the Neutron incident. Limits of the recovery and what escaped The one-time Hub transfer only captured the ATOM sitting in a single attacker-linked address at the moment of the halt. It did not unwind the broader Neutron exploit or recover assets that had already moved elsewhere. Cosmos Labs said roughly 500,000 ATOM had been swapped through THORChain before the halt, and other stolen assets reached networks beyond the Hub. The update did not quantify each account's final claim or guarantee full reimbursement. Cosmos Labs also detailed why an additional 168,990.9 ATOM was not captured. A pending THORChain refund hit the attacker address just after the restart, after the one-time sweep had already executed. Cosmos Labs said validators were aware the refund could arrive, but altering the tested binary to seize it would have required different code and a longer halt. The returned ATOM was later moved to Osmosis and sold. Next steps Neutron's recovery effort still needs to determine who is owed what and propose a distribution route. A Cosmos Hub governance proposal backed by that plan would then provide the public mandate the six multisig signers say they require. Until those steps occur, the secured 1.23 million ATOM remains in custody, with recipients not yet finalized.