Skip to content
A dark teal vault tower rising into shadow, each floor's door fitted with its own lock, while red conduits from a rooftop lever held by a hooded figure run down the facade and bypass every lock.
exploitsSeptember 24, 20264 min read

Neutron's $9.4M Governance Takeover: How $20K of NTRN Bought Admin Over Astroport and Drop

Aron Turner
Aron TurnerCo-Founder & CTO

Updated on September 24, 2026

TL;DR

On September 22, 2026, an attacker passed Neutron governance proposal 9, titled "AIATO: AI Agent Takeover", which reassigned admin rights over 10 Astroport and Drop contracts to the proposer's own address. According to Unchained's on-chain reconstruction, the account carrying most of the yes vote bought about 31.6 million NTRN for 20,199 USDC and staked it less than 12 minutes before voting closed. Within 24 minutes of execution, the attacker migrated all 10 contracts to malicious code and emptied them, a loss GoPlus Security put at $9.4 million. Neutron halted, trapping roughly $5 million, and Cosmos Hub validators stopped their own chain for about 25 hours before moving 1,227,121 ATOM out of the attacker's wallet on restart. The contracts worked as written. Chain governance could replace them, and winning that vote cost $20,199.


What happened on Neutron?

A governance proposal did the stealing. Proposal 9 went through Neutron's expedited track, a three-day vote, and passed with about 82% in favor when voting closed at 10:24 p.m. ET on Monday, September 21 (early on the 22nd in UTC). It carried 11 messages. Each one handed admin control of a Neutron contract to the address that submitted the proposal. Ten of those contracts belonged to Astroport, the DEX, and Drop, the liquid staking protocol.

The split of the damage is reported as $4.9 million from Astroport and $4.4 million from Drop. Neutron stopped producing blocks at 3:43 a.m. ET, a little over five hours after the vote closed. By then about $1.96 million had already left for other chains.

Astroport's first public word was a warning. The protocol told users the attack "may have resulted in the compromise of Astroport contract admin privileges" and asked them to pull liquidity from its pools on every chain. As of September 24, neither Astroport, Drop, nor Neutron has published a technical postmortem, so the mechanics below come from on-chain analysis published by the X user Rarma, GoPlus Security, and the reporting that cites them.


How much was actually lost?

Three numbers are in circulation, and they describe different things.

FigureSourceWhat it measures
$9.3MProtos, per-protocol split$4.9M Astroport plus $4.4M Drop, each rounded
$9.4MGoPlus Security, via The CryptonomistTotal value in the 10 drained contracts
$9.5MCrypto Briefing"Exposed contract values"

We use $9.4 million. The per-protocol figures are each rounded to one decimal, so a $9.3 million sum and a $9.4 million total are the same measurement within rounding, and GoPlus is the only source that published a figure for the whole set of contracts. The $9.5 million number is described as exposure, which is the ceiling.

None of these is what the attacker kept, and the early figures for where the money went do not reconcile with each other. Crypto Briefing reports that only about 20% of the contract value was extracted before Neutron halted, with roughly $5 million trapped on the stopped chain. 20% of $9.4 million is about $1.9 million, which matches the $1.96 million The Cryptonomist says was bridged out, but it leaves about $2.5 million unaccounted for. The positions reported since then fill that gap:

Where the drained value sitsAmountSource
Trapped on halted Neutron~$5MCrypto Briefing, Protos
ATOM moved out of the attacker's wallet by the Cosmos Hub1,227,121 ATOM, ~$2.1MUnchained
Held at an Ethereum address~$1.8MProtos
Returned by THORChain from an unfilled swap168,991 ATOM, ~$294KUnchained
Total~$9.2M

That tally lands within rounding of the $9.4 million total. Our reading is that the 20% figure was an early snapshot taken before the ATOM position on the Hub was counted, so the attacker got roughly $4 million off Neutron, not $1.9 million, and has since lost more than half of it to the Hub and THORChain. The only proceeds still under the attacker's control, on current reporting, are the $1.8 million on Ethereum. Treat that as provisional until a postmortem lands.


What is a contract admin, and why could governance change it?

A CosmWasm contract can have an admin. The admin is the one account allowed to migrate the contract: point the same address, with the same balances, at a new piece of code. Migration is how teams ship fixes without asking users to move funds. It is also the most powerful permission a contract has, because whoever holds it can replace the logic that guards the money.

Astroport and Drop did not hand that permission to a stranger. The Cryptonomist's reporting on the GoPlus analysis puts the real design flaw in one sentence: "Chain-level governance, it turns out, sat above the multisig protections that app developers had put in place to guard their own contracts." The command that crossed that line was MsgUpdateAdmin, which rewrites who the admin is. A passed proposal on Neutron could issue it for contracts the chain's governance controlled, and it did, ten times.

This is the "modules are skeleton keys" problem at chain scale. We wrote about the same shape in the SquidRouterModule Safe exploit: a delegated authority that sits above the owner's own controls, installed for convenience, and never re-examined once the conditions that justified it changed. On Neutron the delegated authority was the whole chain's vote.


Why was the vote so cheap?

Because almost nobody was left holding it. The staked NTRN securing Neutron's governance was worth only about $113,000 at the time of the attack, while that same vote controlled $9.4 million in contract assets. That is an 83 to 1 ratio of what the vote could move to what it cost to defend it.

The background explains the number. In March, Neutron announced a transition to long-term maintenance: Hadron Labs would maintain the network until June 30, 2026, governance would move from Neutron's custom system to the standard Cosmos staking model, and from July to September the DAO's delegations would be gradually withdrawn and burned. Proposal 9 closed on September 21, in the last days of that wind-down. No source has tied the $113,000 figure directly to the withdrawn delegations, so read the connection as our inference. The timing points one way. A chain whose security budget was being deliberately drained still held admin authority over live DeFi contracts.

A dry note on the proposal title: "AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration" is a literal description of what the messages did (the cover story was the truth, dressed as research).


The attack, step by step

StepWhenWhat happenedSource
1Three days before closeProposal 9 submitted on the expedited track, 67% threshold, 1M NTRN deposit, 11 MsgUpdateAdmin messages naming the proposer as adminThe Cryptonomist, Unchained
2During the voteAttacker votes with about 100 NTRN, keeping a low profileThe Cryptonomist
3About 60 minutes before closeAttacker uploads code_id 5399, containing a withdraw_all function that sends funds to a chosen recipientThe Cryptonomist
4About 11 minutes before closeOne account buys about 31.6M NTRN for 20,199 USDC and stakes itUnchained
510:24 p.m. ET, Sept 21Voting closes, proposal passes with about 82% yesUnchained
6Within 24 minutes of execution10 MsgMigrateContract calls move Astroport and Drop contracts to code 5399, then withdraw_all runs on eachThe Cryptonomist
7Hours afterAbout $1.96M bridged out across Neutron, Cosmos Hub, Noble, Axelar, dYdX, Osmosis and EthereumThe Cryptonomist
83:43 a.m. ET, Sept 22Neutron halts, trapping roughly $5MUnchained, Crypto Briefing
9Sept 22 to Sept 23, 12:00 UTCCosmos Hub halts at block 33086740, restarts about 25 hours later and moves 1,227,121 ATOM out of the attacker's wallet in the first blockCrypto Briefing, Unchained

Steps 2 through 4 are the tradecraft. A 100 NTRN vote early says nothing. A code upload an hour before close has no one to call it. A stake that lands 11 minutes before the tally leaves no room for a counter-vote to organize, even if someone had noticed. The attacker spent three days looking like a small, odd proposal, then became the majority at the last possible moment.

Three things the public record does not settle yet. Nobody has published turnout or broken down the rest of the yes vote, but Rarma's analysis has the late-staking account carrying most of it, which points at a thin electorate rather than a crowd of deceived voters. No one has traced where the 20,199 USDC came from. And nothing published describes any delay between the vote passing and the migrations. A drain that finished within 24 minutes of execution suggests there was none.

The path after execution branches, which is why it gets a diagram:

rendering diagram…

Why spending $20,199 to take $9.4 million was rational

The attacker paid 20,199 USDC for a vote that moved $9.4 million, roughly 465 times the stake. Even measured against the $113,000 of total staked NTRN, the trade was 83 to 1. Governance is a price, and on Neutron it was posted in public: about $113,000 of stake defending $9.4 million.

This is the lineage the BonkDAO $20M governance takeover sits in, with one difference that makes Neutron worse. At BonkDAO, the attacker bought control of a treasury, which is the thing a DAO vote is supposed to govern. At Neutron, a chain-level vote reached down into two applications whose teams had their own multisig protections. Astroport's and Drop's liquidity providers never voted on anything. Their security was set by the price of NTRN.

And the audit-complacency foil lands squarely here. An audit of Astroport's pools or Drop's staking logic certifies the code you showed it. It says nothing about who else can swap that code out, and on Neutron the answer was a governance process that anyone with $20,000 could win in the last 11 minutes.


Could anyone have seen it coming?

Yes, for three days. The attack did not hide its payload. Every observable step was on-chain before a dollar moved, and several were sitting in plain view for the whole voting period:

  1. A proposal whose messages named the proposer as admin of 10 DeFi contracts. That was readable from the moment proposal 9 was submitted, three days before it closed.
  2. A new code upload, code_id 5399, about an hour before close, containing a function called withdraw_all.
  3. One account buying about 31.6 million NTRN and staking it roughly 11 minutes before the tally, a stake large enough to decide the vote.
  4. Ten MsgMigrateContract calls against Astroport and Drop contracts inside 24 minutes.

The limit is real: once the vote passed, the migration and drain ran in minutes, and no alert outruns that. The point is that the first signal came three days earlier. A proposal that reassigns admin over protocol contracts is a pageable event in its own right, and so is a vote-deciding stake that appears in the final quarter hour. Either would have given Astroport and Drop time to warn LPs, move treasury-held liquidity, or buy enough NTRN to vote no, and the whole defending stake was worth about $113,000. This is the class of event Tripwire watches: governance proposals whose messages touch your contracts' admin, large last-minute stake changes on the chains you depend on, and code uploads followed by migrations against addresses you care about. Every one of those four signals was a rule, and the first one fired on day one of a three-day window.


Was the Cosmos Hub halt the right call?

Undecided, and it deserves more debate than it will get. The Cosmos Hub validators halted the network at block 33086740 on September 22 and resumed at 12:00 UTC the next day. In the first block after restart, 1,227,121 ATOM moved from the attacker's wallet to a newly created address. Reporting has not explained the mechanism or said who controls the new address.

That recovered about $2.1 million. It also established that the Hub's validator set will stop the chain and move a balance when enough of them agree the balance is stolen. Many users will call that a feature. Every protocol that builds on the Hub now has a new, unwritten term in its threat model.


What operators should do now

  1. List every party that can migrate your contracts. On CosmWasm chains that means the contract admin and anything above it, including chain governance. If a chain-level proposal can issue MsgUpdateAdmin for your code, your multisig is advisory.
  2. Price your governance. Compare the cost of a passing vote (staked value times your threshold) against the assets that vote can reach. An 83 to 1 gap is a public bounty.
  3. Treat a chain wind-down as a security event. If the chain you deploy on announces maintenance mode, falling stake, or withdrawn delegations, re-evaluate who can touch your contracts before the security budget reaches zero, not after.
  4. Alert on proposals, not only transactions. Parse every proposal's messages on the chains you depend on and page when one names your contract addresses or code IDs.
  5. Watch late stake. A single account staking a vote-deciding balance in the last hour of a proposal is the clearest signal a bought vote leaves.
  6. Remove the delegated authority you no longer need. If chain governance held admin for a migration plan that is over, clear the admin or move it to a timelocked multisig you control.

Frequently Asked Questions

Was the Neutron exploit a smart contract bug?

No. The Astroport and Drop contracts behaved as written. An attacker passed a governance proposal that made their own address the admin of 10 contracts, then used the admin's legitimate migrate permission to replace the code with a withdraw_all function.

How much did the Neutron governance attack cost the attacker?

About 20,199 USDC. That bought roughly 31.6 million NTRN, which the attacker staked less than 12 minutes before proposal 9's vote closed, according to on-chain analysis summarized by Unchained.

How much of the $9.4 million did the attacker keep?

Not most of it. Roughly $5 million was trapped when Neutron halted, the Cosmos Hub moved about $2.1 million in ATOM out of the attacker's wallet, and THORChain returned about $294,000. About $1.8 million was reported sitting at an Ethereum address, and the net figure is still changing.

Can Cosmos chain governance migrate any CosmWasm contract?

No. Governance can only reassign or use admin rights over contracts where governance is the admin or sits above it. On Neutron, chain governance sat above the multisigs Astroport and Drop used, so a passed proposal could rewrite their admin. Check your own contract's admin chain before assuming you are out of reach.

Has Neutron published a postmortem?

Not yet. As of September 24, 2026, the public account comes from on-chain analysis by the X user Rarma and GoPlus Security, plus press reporting. Figures here should be treated as reported until a postmortem lands.


Sources / References

Aron Turner
Aron Turner

Co-Founder & CTO

CTO of SigIntZero. Engineering leadership, infrastructure architecture, and security tooling.