TL;DR
On September 22, 2026, an attacker passed Neutron governance proposal 9, titled "AIATO: AI Agent Takeover", which reassigned admin rights over 10 Astroport and Drop contracts to the proposer's own address. According to Unchained's on-chain reconstruction, the account carrying most of the yes vote bought about 31.6 million NTRN for 20,199 USDC and staked it less than 12 minutes before voting closed. Within 24 minutes of execution, the attacker migrated all 10 contracts to malicious code and emptied them, a loss GoPlus Security put at $9.4 million. Neutron halted, trapping roughly $5 million, and Cosmos Hub validators stopped their own chain for about 25 hours before moving 1,227,121 ATOM out of the attacker's wallet on restart. The contracts worked as written. Chain governance could replace them, and winning that vote cost $20,199.
What happened on Neutron?
A governance proposal did the stealing. Proposal 9 went through Neutron's expedited track, a three-day vote, and passed with about 82% in favor when voting closed at 10:24 p.m. ET on Monday, September 21 (early on the 22nd in UTC). It carried 11 messages. Each one handed admin control of a Neutron contract to the address that submitted the proposal. Ten of those contracts belonged to Astroport, the DEX, and Drop, the liquid staking protocol.
The split of the damage is reported as $4.9 million from Astroport and $4.4 million from Drop. Neutron stopped producing blocks at 3:43 a.m. ET, a little over five hours after the vote closed. By then about $1.96 million had already left for other chains.
Astroport's first public word was a warning. The protocol told users the attack "may have resulted in the compromise of Astroport contract admin privileges" and asked them to pull liquidity from its pools on every chain. As of September 24, neither Astroport, Drop, nor Neutron has published a technical postmortem, so the mechanics below come from on-chain analysis published by the X user Rarma, GoPlus Security, and the reporting that cites them.
How much was actually lost?
Three numbers are in circulation, and they describe different things.
| Figure | Source | What it measures |
|---|---|---|
| $9.3M | Protos, per-protocol split | $4.9M Astroport plus $4.4M Drop, each rounded |
| $9.4M | GoPlus Security, via The Cryptonomist | Total value in the 10 drained contracts |
| $9.5M | Crypto Briefing | "Exposed contract values" |
We use $9.4 million. The per-protocol figures are each rounded to one decimal, so a $9.3 million sum and a $9.4 million total are the same measurement within rounding, and GoPlus is the only source that published a figure for the whole set of contracts. The $9.5 million number is described as exposure, which is the ceiling.
None of these is what the attacker kept, and the early figures for where the money went do not reconcile with each other. Crypto Briefing reports that only about 20% of the contract value was extracted before Neutron halted, with roughly $5 million trapped on the stopped chain. 20% of $9.4 million is about $1.9 million, which matches the $1.96 million The Cryptonomist says was bridged out, but it leaves about $2.5 million unaccounted for. The positions reported since then fill that gap:
| Where the drained value sits | Amount | Source |
|---|---|---|
| Trapped on halted Neutron | ~$5M | Crypto Briefing, Protos |
| ATOM moved out of the attacker's wallet by the Cosmos Hub | 1,227,121 ATOM, ~$2.1M | Unchained |
| Held at an Ethereum address | ~$1.8M | Protos |
| Returned by THORChain from an unfilled swap | 168,991 ATOM, ~$294K | Unchained |
| Total | ~$9.2M |
That tally lands within rounding of the $9.4 million total. Our reading is that the 20% figure was an early snapshot taken before the ATOM position on the Hub was counted, so the attacker got roughly $4 million off Neutron, not $1.9 million, and has since lost more than half of it to the Hub and THORChain. The only proceeds still under the attacker's control, on current reporting, are the $1.8 million on Ethereum. Treat that as provisional until a postmortem lands.
What is a contract admin, and why could governance change it?
A CosmWasm contract can have an admin. The admin is the one account allowed to migrate the contract: point the same address, with the same balances, at a new piece of code. Migration is how teams ship fixes without asking users to move funds. It is also the most powerful permission a contract has, because whoever holds it can replace the logic that guards the money.
Astroport and Drop did not hand that permission to a stranger. The Cryptonomist's reporting on the GoPlus analysis puts the real design flaw in one sentence: "Chain-level governance, it turns out, sat above the multisig protections that app developers had put in place to guard their own contracts." The command that crossed that line was MsgUpdateAdmin, which rewrites who the admin is. A passed proposal on Neutron could issue it for contracts the chain's governance controlled, and it did, ten times.
This is the "modules are skeleton keys" problem at chain scale. We wrote about the same shape in the SquidRouterModule Safe exploit: a delegated authority that sits above the owner's own controls, installed for convenience, and never re-examined once the conditions that justified it changed. On Neutron the delegated authority was the whole chain's vote.
Why was the vote so cheap?
Because almost nobody was left holding it. The staked NTRN securing Neutron's governance was worth only about $113,000 at the time of the attack, while that same vote controlled $9.4 million in contract assets. That is an 83 to 1 ratio of what the vote could move to what it cost to defend it.
The background explains the number. In March, Neutron announced a transition to long-term maintenance: Hadron Labs would maintain the network until June 30, 2026, governance would move from Neutron's custom system to the standard Cosmos staking model, and from July to September the DAO's delegations would be gradually withdrawn and burned. Proposal 9 closed on September 21, in the last days of that wind-down. No source has tied the $113,000 figure directly to the withdrawn delegations, so read the connection as our inference. The timing points one way. A chain whose security budget was being deliberately drained still held admin authority over live DeFi contracts.
A dry note on the proposal title: "AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration" is a literal description of what the messages did (the cover story was the truth, dressed as research).
The attack, step by step
| Step | When | What happened | Source |
|---|---|---|---|
| 1 | Three days before close | Proposal 9 submitted on the expedited track, 67% threshold, 1M NTRN deposit, 11 MsgUpdateAdmin messages naming the proposer as admin | The Cryptonomist, Unchained |
| 2 | During the vote | Attacker votes with about 100 NTRN, keeping a low profile | The Cryptonomist |
| 3 | About 60 minutes before close | Attacker uploads code_id 5399, containing a withdraw_all function that sends funds to a chosen recipient | The Cryptonomist |
| 4 | About 11 minutes before close | One account buys about 31.6M NTRN for 20,199 USDC and stakes it | Unchained |
| 5 | 10:24 p.m. ET, Sept 21 | Voting closes, proposal passes with about 82% yes | Unchained |
| 6 | Within 24 minutes of execution | 10 MsgMigrateContract calls move Astroport and Drop contracts to code 5399, then withdraw_all runs on each | The Cryptonomist |
| 7 | Hours after | About $1.96M bridged out across Neutron, Cosmos Hub, Noble, Axelar, dYdX, Osmosis and Ethereum | The Cryptonomist |
| 8 | 3:43 a.m. ET, Sept 22 | Neutron halts, trapping roughly $5M | Unchained, Crypto Briefing |
| 9 | Sept 22 to Sept 23, 12:00 UTC | Cosmos Hub halts at block 33086740, restarts about 25 hours later and moves 1,227,121 ATOM out of the attacker's wallet in the first block | Crypto Briefing, Unchained |
Steps 2 through 4 are the tradecraft. A 100 NTRN vote early says nothing. A code upload an hour before close has no one to call it. A stake that lands 11 minutes before the tally leaves no room for a counter-vote to organize, even if someone had noticed. The attacker spent three days looking like a small, odd proposal, then became the majority at the last possible moment.
Three things the public record does not settle yet. Nobody has published turnout or broken down the rest of the yes vote, but Rarma's analysis has the late-staking account carrying most of it, which points at a thin electorate rather than a crowd of deceived voters. No one has traced where the 20,199 USDC came from. And nothing published describes any delay between the vote passing and the migrations. A drain that finished within 24 minutes of execution suggests there was none.
The path after execution branches, which is why it gets a diagram:
Why spending $20,199 to take $9.4 million was rational
The attacker paid 20,199 USDC for a vote that moved $9.4 million, roughly 465 times the stake. Even measured against the $113,000 of total staked NTRN, the trade was 83 to 1. Governance is a price, and on Neutron it was posted in public: about $113,000 of stake defending $9.4 million.
This is the lineage the BonkDAO $20M governance takeover sits in, with one difference that makes Neutron worse. At BonkDAO, the attacker bought control of a treasury, which is the thing a DAO vote is supposed to govern. At Neutron, a chain-level vote reached down into two applications whose teams had their own multisig protections. Astroport's and Drop's liquidity providers never voted on anything. Their security was set by the price of NTRN.
And the audit-complacency foil lands squarely here. An audit of Astroport's pools or Drop's staking logic certifies the code you showed it. It says nothing about who else can swap that code out, and on Neutron the answer was a governance process that anyone with $20,000 could win in the last 11 minutes.
Could anyone have seen it coming?
Yes, for three days. The attack did not hide its payload. Every observable step was on-chain before a dollar moved, and several were sitting in plain view for the whole voting period:
- A proposal whose messages named the proposer as admin of 10 DeFi contracts. That was readable from the moment proposal 9 was submitted, three days before it closed.
- A new code upload,
code_id 5399, about an hour before close, containing a function calledwithdraw_all. - One account buying about 31.6 million NTRN and staking it roughly 11 minutes before the tally, a stake large enough to decide the vote.
- Ten
MsgMigrateContractcalls against Astroport and Drop contracts inside 24 minutes.
The limit is real: once the vote passed, the migration and drain ran in minutes, and no alert outruns that. The point is that the first signal came three days earlier. A proposal that reassigns admin over protocol contracts is a pageable event in its own right, and so is a vote-deciding stake that appears in the final quarter hour. Either would have given Astroport and Drop time to warn LPs, move treasury-held liquidity, or buy enough NTRN to vote no, and the whole defending stake was worth about $113,000. This is the class of event Tripwire watches: governance proposals whose messages touch your contracts' admin, large last-minute stake changes on the chains you depend on, and code uploads followed by migrations against addresses you care about. Every one of those four signals was a rule, and the first one fired on day one of a three-day window.
Was the Cosmos Hub halt the right call?
Undecided, and it deserves more debate than it will get. The Cosmos Hub validators halted the network at block 33086740 on September 22 and resumed at 12:00 UTC the next day. In the first block after restart, 1,227,121 ATOM moved from the attacker's wallet to a newly created address. Reporting has not explained the mechanism or said who controls the new address.
That recovered about $2.1 million. It also established that the Hub's validator set will stop the chain and move a balance when enough of them agree the balance is stolen. Many users will call that a feature. Every protocol that builds on the Hub now has a new, unwritten term in its threat model.
What operators should do now
- List every party that can migrate your contracts. On CosmWasm chains that means the contract admin and anything above it, including chain governance. If a chain-level proposal can issue
MsgUpdateAdminfor your code, your multisig is advisory. - Price your governance. Compare the cost of a passing vote (staked value times your threshold) against the assets that vote can reach. An 83 to 1 gap is a public bounty.
- Treat a chain wind-down as a security event. If the chain you deploy on announces maintenance mode, falling stake, or withdrawn delegations, re-evaluate who can touch your contracts before the security budget reaches zero, not after.
- Alert on proposals, not only transactions. Parse every proposal's messages on the chains you depend on and page when one names your contract addresses or code IDs.
- Watch late stake. A single account staking a vote-deciding balance in the last hour of a proposal is the clearest signal a bought vote leaves.
- Remove the delegated authority you no longer need. If chain governance held admin for a migration plan that is over, clear the admin or move it to a timelocked multisig you control.
Frequently Asked Questions
Was the Neutron exploit a smart contract bug?
No. The Astroport and Drop contracts behaved as written. An attacker passed a governance proposal that made their own address the admin of 10 contracts, then used the admin's legitimate migrate permission to replace the code with a withdraw_all function.
How much did the Neutron governance attack cost the attacker?
About 20,199 USDC. That bought roughly 31.6 million NTRN, which the attacker staked less than 12 minutes before proposal 9's vote closed, according to on-chain analysis summarized by Unchained.
How much of the $9.4 million did the attacker keep?
Not most of it. Roughly $5 million was trapped when Neutron halted, the Cosmos Hub moved about $2.1 million in ATOM out of the attacker's wallet, and THORChain returned about $294,000. About $1.8 million was reported sitting at an Ethereum address, and the net figure is still changing.
Can Cosmos chain governance migrate any CosmWasm contract?
No. Governance can only reassign or use admin rights over contracts where governance is the admin or sits above it. On Neutron, chain governance sat above the multisigs Astroport and Drop used, so a passed proposal could rewrite their admin. Check your own contract's admin chain before assuming you are out of reach.
Has Neutron published a postmortem?
Not yet. As of September 24, 2026, the public account comes from on-chain analysis by the X user Rarma and GoPlus Security, plus press reporting. Figures here should be treated as reported until a postmortem lands.
Sources / References
- Unchained: Cosmos Hub Restarts and Moves $2.1 Million in Stolen Tokens Out of an Attacker's Wallet
- The Cryptonomist: Neutron Governance Attack Exposes $9.4M Blockchain Exploit
- Protos: Cosmos hub halts for 24 hours after Neutron governance attack
- Crypto Briefing: Cosmos Hub restarts after 25-hour halt, moves $2M in stolen tokens from attacker's wallet
- KuCoin News: Astroport Warns of Potential Admin Privilege Theft Following Neutron Attack
- PANews: The Cosmos ecosystem project Neutron will transition to a long-term maintenance model, with many services being gradually shut down



