Neutron governance exploit drains $9.4M via flash-bought voting power; Cosmos Hub validators halt chain 24 hours to recover $1.23M ATOM.
Security & Exploits ·
An attacker exploited Neutron governance by acquiring approximately $20K in voting power through a flash purchase and wielding it to gain administrative control over roughly $9.4M in assets across the Astroport and Drop Money contracts. The attacker staked the purchased voting tokens 12 minutes before an expedited proposal concluded, enabling the seizure of funds before validators could respond. Approximately $1.96M had already been moved out when the attack was detected.
In response, Cosmos Hub validators initiated a coordinated chain halt lasting 24 hours and 48 minutes to intercept and recover assets. During this suspension, approximately 1.23M ATOM was redirected from the attacker's wallet back toward affected users. The recovery operation required unprecedented coordination across the network to reverse the damage.
The incident highlights a structural vulnerability in Cosmos SDK governance: voting power acquired with minimal capital can control substantially larger treasury reserves. This asymmetry, combined with expedited proposal timelines, created conditions for rapid asset capture. The event may prompt other chains using Cosmos SDK to revisit how administrative migrations and governance proposal acceleration are implemented, as reported by The Defiant.