Quick Take
- Hub validators transferred 1,227,121.37 stolen ATOM into a recovery multisig after the Neutron attack.
- The emergency patch secured one balance but did not identify claimants or authorize refunds.
- Signers say they will wait for a Neutron recovery plan and passed Hub proposal before releasing the funds.
An attacker moved roughly 1.73 million stolen ATOM from Neutron to the Cosmos Hub during a Sept. 22 governance attack. Hub validators secured 1,227,121.37 ATOM of that flow in an emergency software patch, but the six signers holding it say a separate Hub governance proposal must pass before they release the funds to affected users and protocols.
That condition, detailed in a Sept. 25 account from Cosmos Labs, separates the emergency action validators took to prevent further outflows from the decision over who should receive the money. The recovery address held 1,227,121.374688 ATOM in a Hub balance query at 15:40 UTC on Sept. 26. The tokens were in custody, while Cosmos Labs said the Neutron response team was still preparing the evidence and distribution plan that would support a return.
How validators secured the ATOM
The attack began on Neutron on Sept. 22, when a governance proposal gave the attacker administrative control over contracts used by Astroport and other protocols, according to the Hub maintainers. The attacker moved some of the stolen assets to other networks, including roughly 1.73 million ATOM to the Cosmos Hub. The Hub itself was not exploited; it became the place where part of the stolen balance could still be intercepted.
As the attacker swapped and bridged ATOM, Hub validators halted their chain at height 33,086,740. They then agreed to restart on a patched version of the Gaia software, v28.3.0. At the first height after the halt, the patch made a one-time state change that transferred 1,227,121.37 ATOM from the attacker-linked Hub address to a recovery multisig before ordinary transactions resumed. The Hub's Sept. 24 update says the binary was scoped to that one source account and did not change other user balances or delegations.
The process was a coordinated validator update, not an on-chain vote authorizing compensation. Cosmos Labs says validators received the written source and destination addresses, the list of six signers and the proposed scope before it built and distributed the binary. Validators representing more than 67% of Hub voting power had confirmed installation before the Sept. 23 restart. Blocks resumed at 12:00 UTC, and the transfer took effect at about 12:06 UTC.
The maintainers said the binary was tested against a fork of mainnet state and distributed with a checksum. Its source diff was withheld at the time because publication would expose security fixes in the underlying v28.2.0 release that remained under a coordinated disclosure embargo. Cosmos Labs said it expected to publish the diff after the embargo lifted. That was its Sept. 25 disclosure timetable, not confirmation of a later release.
Custody of stolen ATOM does not settle who gets paid
Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu are the six validators named as multisig signers. Any four signatures meet the wallet's technical threshold for a transaction. The signers have stated a separate condition for using that capability: a passed Cosmos Hub signaling proposal must authorize a legitimate transfer. Cosmos Labs says it has no key to the wallet.
This creates two distinct forms of control. A supermajority of validators agreed to change Hub state during the halt so the attacker could not move the balance already there. The custody signers now hold that stolen ATOM, but say they will wait for a public governance mandate before deciding a destination. The emergency patch did not identify every valid claimant or approve a distribution schedule.
The proposed route starts on Neutron's side. Cosmos Labs said Neutron had relaunched with mitigations by Sept. 25, while contributors and affected protocols, including Astroport and Drop, were preparing evidence of what was taken and where recovered assets should go. The response team was expected to bring or back a Hub proposal in the following week. Whether Neutron governance also takes a vote is for that network to decide, the Hub account said.
The Hub governance proposal list checked at 15:40 UTC on Sept. 26 showed no passed mandate for the recovery multisig among its visible post-incident entries. Its latest proposal, 1057, concerned recovery of a Realio IBC light client. Proposal 1056, titled “ATOM Refund & Justice Bounty,” was still in voting and sought a different refund and bounty; it did not authorize the Neutron response team's distribution from this multisig. The governance requirement therefore remained prospective at the time of the check.
The Hub transfer covered the ATOM sitting in one attacker-linked address at the halt. It did not reverse the wider Neutron attack. Cosmos Labs said roughly 500,000 ATOM had already been swapped through THORChain before the halt, while other stolen assets reached networks beyond the Hub. Its account does not establish the final size of each affected account's claim or promise full reimbursement.
Why the patch could not capture later funds
Another 168,990.9 ATOM illustrates the patch's time limit. A pending THORChain refund reached the attacker address just after the restart, after the one-time transfer had executed. Cosmos Labs said validators knew the refund might arrive, but changing the tested binary to capture it would have required different code and a longer halt. The returned ATOM was moved to Osmosis and sold. It was a later arrival at the attacker address, separate from the balance already transferred to the multisig. A rule applied once at the restart could not automatically sweep a later deposit.
The Neutron-side recovery plan must still establish who is owed what and where the funds should go. A Hub proposal backed by that plan would then give the six signers the public mandate they say they require. Until those steps occur, the secured ATOM remains available for recovery, with its recipients unresolved.




