An attacker moved roughly 1.73 million stolen ATOM from Neutron to the Cosmos Hub during the Sept. 22 governance attack. Hub validators halted the chain and used a patched Gaia v28.3.0 binary to transfer 1,227,121.37 ATOM into a recovery multisig. The six signers now require a separate Cosmos Hub governance mandate before releasing funds to affected users and protocols.
The emergency intervention was designed to stop further movement, not authorize compensation. More than 67% of Hub voting power confirmed the patched software before the Sept. 23 restart, and the one-time state change targeted a single attacker-linked address without altering other balances or delegations.
Why it matters
The incident separates custody from repayment. Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu hold the recovery multisig, with four signatures technically sufficient for a transaction. The signers have said they will not use that authority without a passed public proposal.
The proposed distribution depends on evidence from Neutron contributors and affected protocols, including Astroport and Drop. That process must determine who is owed what and where the recovered ATOM should go. The Cosmos Hub had no visible passed mandate for this multisig at 15:40 UTC on Sept. 26.
Market impact
The patch recovered the ATOM already sitting in the attacker-linked Hub address, but it did not reverse the wider Neutron exploit. Cosmos Labs said roughly 500,000 ATOM had already been swapped through THORChain, while another 168,990.9 ATOM arrived through a pending refund after the restart and was later moved to Osmosis and sold.
The immediate market question is governance execution, not just recovery. Until the Hub proposal passes and the evidence-based distribution plan is approved, 1.23 million ATOM remains secured but its recipients are unresolved.
Frequently asked questions
-
How much stolen ATOM did Cosmos Hub secure?
Validators transferred 1,227,121.37 ATOM from an attacker-linked Hub address into a recovery multisig after the chain restart.
-
Why has the recovered ATOM not been refunded yet?
The six recovery multisig signers say they require a passed Cosmos Hub governance proposal before releasing the funds to affected users and protocols.
-
Was the Cosmos Hub itself exploited in the attack?
No. The Hub became the destination where part of the stolen ATOM could be intercepted. The emergency patch targeted one attacker-linked address and did not alter other balances or delegations.
-
Which groups are involved in distributing the recovered funds?
Neutron contributors and affected protocols, including Astroport and Drop, are preparing evidence and a distribution plan to determine claimants and allocations.
-
How much ATOM escaped the emergency recovery process?
Cosmos Labs said roughly 500,000 ATOM had already moved through THORChain. Another 168,990.9 ATOM arrived after the one-time patch transfer and was later moved to Osmosis and sold.
CryptoSlate