Cosmos Hub secures 1.23 million ATOM after Neutron attack

요약:Cosmos Hub secured 1.23 million ATOM after the Neutron attack. Returning the funds requires a governance vote.

Cosmos Hub validators have secured 1.23 million ATOM taken in a Neutron governance attack after halting the network for about 24.5 hours and moving the tokens to a recovery wallet.

Summary

  • Roughly 1.73 million stolen ATOM reached the Cosmos Hub from Neutron.
  • Validators moved 1,227,121 ATOM to a wallet requiring four of six signers to approve a transaction.
  • Another 168,990.9 ATOM reached the attacker after the restart and was moved to Osmosis and sold.
  • Returning the secured funds will require a Cosmos Hub governance vote.

Cosmos Labs said in a Sep. 25 update that the Hub itself was not attacked and Hub user funds were unaffected. The stolen ATOM came from Neutron, where a malicious governance proposal gave the attacker control over contracts used by Astroport and other protocols.

At the time of the Hub‘s halt, 1,227,121 ATOM remained in the attacker’s address. Validators restarted the network on Sep. 23 using Gaia v28.3.0, a software update that moved the balance to a wallet controlled by six community validators. Four of them must approve any transaction from that wallet.

The tokens are being held while the Neutron recovery team prepares a plan. Under the arrangement described by Cosmos Labs, the signers cannot return the funds until a Cosmos Hub governance proposal authorizes the transfer.

You might also like:

Cosmos says bank tokenization is moving beyond pilots

Cosmos Hub halt stopped the remaining ATOM from leaving

After the Neutron attack on Sep. 22, the attacker sent stolen assets to several chains and began swapping some of the ATOM through THORChain, according to the Cosmos Labs account. About 1.73 million ATOM reached the Hub, where the attacker could have continued moving it even after Neutron stopped producing blocks.

Neutron contributors and community members alerted Hub validators and Cosmos Labs at about 09:50 UTC. Validators representing more than one-third of the Hubs voting power then stopped their nodes, bringing the network to a halt at block 33,086,740 by about 11:18 UTC.

During the pause, Cosmos Labs prepared a one-time software change at the validators‘ request. Its written plan identified the attacker’s address, the destination wallet, the six proposed signers and the single account that the update would affect. Validators received that plan before the patched software was distributed.

Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu agreed to hold the six signing keys. Cosmos Labs said the signers independently checked the wallet address and verified it with a test transaction before developers added it to the update.

By the time of the scheduled restart, validators representing more than two-thirds of voting power had installed v28.3.0. Block production resumed at 12:00 UTC on Sep. 23, and the 1,227,121.37 ATOM transfer took effect about six minutes later. Cosmos Labs said 174 of the Hubs 180 validators were online by the end of that day.

The participating validators included Coinbase and Kraken, according to the update. Their role was part of the Hubs coordinated software restart; Cosmos Labs said exchanges and other operators were subsequently told that deposits and withdrawals could resume once the network was stable.

Some ATOM left before and after the restart

The secured balance represents only the ATOM still in the attackers Hub address when validators halted the chain. Cosmos Labs said roughly 500,000 ATOM had already been swapped for ETH through THORChain before the halt and could not be recovered through the Hub update.

A separate THORChain transaction returned 168,990.9 ATOM to the attackers address shortly after block production resumed. The attacker moved that balance to Osmosis and sold it, according to the forum post.

Cosmos Labs said the possible refund was identified while validators were preparing to restart, after the patched software had been distributed and installed by many operators. The update authorized a single transfer of the balance present at the halt height. It did not block later transactions from the attackers address or move funds that arrived after the restart.

The Hub response also did not cover assets sent to other networks. Cosmos Labs identified stolen funds that had moved through dYdX, Noble, Osmosis, Axelar and EVM chains, as well as assets still on Neutron. Teams handling those networks are coordinating their own recovery efforts, the company said.

An earlier, separate incident affected software used by other Cosmos networks. In August, crypto.news reported that attackers exploited a Cosmos EVM flaw across six chains and converted stolen tokens into about $5.72 million in other assets. Cosmos Labs account of the Neutron case describes a governance attack on Neutron, not that Cosmos EVM flaw.

ATOM return depends on a Hub governance vote

The six signers have agreed to hold the recovered ATOM without staking, lending or trading it, Cosmos Labs said. They describe their role as carrying out an authorized return, rather than deciding for themselves which affected accounts should receive funds.

A Cosmos Hub governance proposal must pass before the wallet can make that transfer. The Neutron recovery team expects to submit a proposal in the coming week, once it has set out the proposed destination and return process. Neutrons maintainers also expect to publish their account of the attack early next week.

The governance requirement gives ATOM holders a direct role in the next step. Cosmos Hub governance has previously decided other matters affecting the token: a March Osmosis proposal sought to convert OSMO to ATOM and place unclaimed tokens in the Hub community pool, though a later Hub vote rejected that plan.

For the Neutron recovery, Cosmos Labs said the secured ATOM remains in the validator wallet while the proposal is prepared. The company has shared the attackers addresses with more than 30 exchanges, bridges, and custodians, and said several have confirmed that they blocked the addresses.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

10년물 국채 수익률이 19년 만에 최고치를 기록하면서 비트코인 8만4,000달러 아래로 하락

다음

전 Hack VC 파트너 신주 추앙의 사망, 자살로 판정