Cosmos Hub resumed block production at 12:00 UTC on Wednesday after validators kept the network offline for more than 24 hours following a governance attack on Neutron, a chain in the Cosmos ecosystem.

The incident began with a malicious Neutron proposal that enabled an attacker to seize control of two applications built on the chain, Astroport and Drop. The attack initially resulted in losses estimated at $9.5 million, although much of that value was later stranded on networks that were paused or halted in response.

Malicious proposal passed on Neutron

According to the source report, the attack centered on a proposal titled “AI Agent Takeover” that was approved through Neutron’s governance system. Once passed, it gave the attacker control over Astroport and Drop, two Neutron-based applications.

The attacker then drained assets from both protocols. The reported amounts were about $4.9 million from Astroport and $4.4 million from Drop. Protos said the attacker spent $20,199 to obtain the NTRN tokens needed to push the proposal through.

Networks paused to contain the damage

After the attack was discovered, Neutron was paused. That move trapped an estimated $5 million in assets on the network, limiting what the attacker could immediately extract.

Cosmos Hub validators then halted block production at height 33086740. The Hub shutdown locked a further 1.2 million ATOM, valued at more than $2.2 million, in an address controlled by the attacker. A restart was scheduled with a queued refund designed to return that trapped ATOM balance once the chain came back online.

Only part of the stolen funds appeared reachable

While the initial impact was put at $9.5 million, the report said the attacker could access only around 20% of that amount, with the remainder stuck on halted networks.

The attacker’s Ethereum address reportedly held $1.8 million. In addition, a transfer worth more than $300,000 was pending on THORChain, but that transaction was expected to be refunded back to the Cosmos Hub address once the restart was completed.

Another security shock for Cosmos

The event is described as the third major security scare to hit the Cosmos ecosystem in recent months. It follows a bug in Cosmos Labs’ Cosmos EVM module that reportedly led to exploits across four blockchains.

It also comes after another disclosed incident in which 40 nBTC were said to have been minted out of thin air. With block production now restored on Cosmos Hub, the confirmed next step from the response described in the report was the refund of the trapped ATOM included in the chain’s restart process.

Source: protos.com