• An attacker took administrative control of contracts on the Neutron network on 22 September and moved roughly 1.73 million ATOM to the Cosmos Hub.
  • Hub locked 1,227,121 of those into a recovery address through an emergency software patch. The Hub itself was not exploited.
  • The six signers now holding that balance say a separate Hub governance proposal has to pass before any of it goes back to affected users and .

Most of the money an attacker took from Neutron users last week has been found, identified down to six decimal places, and put somewhere it cannot be spent. Nobody who lost funds has been repaid, and under the terms the holders have set, nobody will be until a vote passes.

If you had money in one of the affected protocols, the unusual part of this is that the coins still exist and everyone can see them. What decides whether you get them back is not a police investigation or a court. It is a governance vote among ATOM holders, most of whom were not affected, on a proposal that had not been written when the tokens were seized.

A note on sourcing: we have not seen the Cosmos Labs account this is drawn from. Everything below comes from CryptoSlate’s write-up of it, and the figures are as that report gives them.

What happened on Neutron

Neutron is a network built in the Cosmos ecosystem, and like most of that ecosystem it is run by governance: token holders submit proposals, other holders vote, and proposals that pass execute automatically. There is no board meeting in between. The chain does what the vote said.

On 22 September, according to the Hub maintainers, a proposal passed that handed the attacker administrative control over contracts used by Astroport and other protocols on the network. That is the whole mechanism. Nothing was broken into. The system was asked to hand over the keys in the way it is designed to hand over keys, and it did.

It is worth being clear about what that means for an ordinary holder, because the usual advice does not cover it. Keeping your own keys protects you from an exchange collapsing. It does not protect you from the contract your money is deposited in having its owner changed by a vote. Our guide to self-custody covers what holding your own keys does and does not cover.

Why the Hub could act at all

The attacker moved assets off Neutron to several other networks, including roughly 1.73 million ATOM to the Cosmos Hub. The Hub is a separate chain with its own validators, and it was not exploited. It simply became the place the tokens landed.

Hub validators responded with an emergency software patch, a coordinated upgrade agreed and run by the operators who produce the chain’s blocks. The patch moved 1,227,121.37 ATOM into a recovery address controlled by six signers, meaning several of them have to agree before anything moves out of it. A balance query on 26 September at 15:40 UTC showed 1,227,121.374688 ATOM still sitting there.

Freezing it took days. Deciding what to do with it has not started in earnest: Cosmos Labs said the Neutron response team was still putting together the evidence and the distribution plan that a return would rest on.

The half million that is not in the address

Roughly 1.73 million ATOM moved. Roughly 1.23 million was secured. The difference, around 500,000 tokens, is not accounted for in the report, and there is no explanation of whether it was moved on before the patch took effect, swapped, or is being tracked somewhere else.

No dollar figure appears in the source either, and we are not going to put one in. ATOM has moved a long way this year and any conversion would tell you more about the date we picked than about the loss.

Other chains have answered this differently

There is no standard response to this. In the past fortnight, according to reporting at the time, both Zano and Cronos dealt with incidents by rewinding their own chains, erasing the transactions rather than chasing the funds. That is a heavier intervention: it rewrites settled history for everyone, not just the attacker.

What the Cosmos Hub validators did is narrower. They stopped one balance from moving and left the question of ownership to a later vote. It is a more restrained use of power, and it is also slower, which is the cost being paid by the people waiting.

What the vote actually decides

A minimalist white door set against a plain wall, casting geometric shadows in natural sunlight.
A closed door in plain sunlight: the stolen ATOM sits behind something similar, shut but not locked, until validators vote on who gets to open it. Photo by Simeon Galabov on Pexels.

Not whether the freeze was legitimate. That has already happened. The proposal decides who is entitled to the tokens, on what evidence, and in what proportions, which is the harder problem: funds pooled in shared contracts do not come with names attached, and working out who was holding what at the moment of the attack is an accounting exercise before it is a political one.

That this is being designed now, under pressure, with the money already in custody, is a fair criticism of the ecosystem rather than of the validators who acted. Chains that can freeze funds by emergency patch should have a written path for releasing them before the day they need it.

What to watch

Whether the proposal actually goes , and what it says about the missing 500,000 ATOM. A distribution plan covering only the recovered portion makes some users whole and leaves others with nothing, and the split between those two groups will be set by that document.

After that, the vote itself. A rejection would leave 1.23 million identified, recovered tokens sitting in an address with no agreed owner, which is a worse outcome than it sounds and a precedent every other chain in the ecosystem will read carefully.