Cosmos Hub restarts after 25-hour halt, moves $2M in stolen tokens from attacker’s wallet
Validators coordinated a rare full network shutdown to freeze 1.2 million ATOM tied to a governance exploit that drained $9.5 million from Neutron applications
The Cosmos Hub is back online after validators pulled the emergency brake for 25 hours, freezing the network to prevent a governance attacker from moving roughly 1.2 million ATOM, worth over $2.2 million, off the chain.
The coordinated halt, which began at block height 33086740 on September 22, ended at 12:00 UTC on September 23 when normal block production resumed. As part of the restart, the network successfully moved the stolen ATOM out of the attacker’s wallet.
A $20K exploit that nearly cost $9.5 million
The root cause wasn’t on the Cosmos Hub itself. It started on Neutron, a smart contract platform in the Cosmos ecosystem, where an attacker used a governance proposal to seize control of two applications: Astroport and Drop.
The total cost of entry for the attacker was about $20,200 in NTRN tokens. The payout was considerably more generous, with contracts worth an estimated $9.5 million exposed to draining.
The attacker managed to extract roughly 20% of those contract values before Neutron independently halted its own operations, trapping about $5 million in assets. The problem was that a portion of the stolen funds, specifically 1.2 million ATOM, had already made it to a Cosmos Hub address. With ATOM sitting on a separate chain from Neutron, a separate intervention was needed. That’s where the Hub validators stepped in.
Shutting down a blockchain on purpose
For 25 hours, the Cosmos Hub was essentially frozen in place. Letting the chain run meant the attacker could have transferred, swapped, or bridged the stolen ATOM to places where recovery becomes nearly impossible. Halting the chain meant temporary disruption for every user but kept the stolen tokens exactly where validators could reach them.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
No user funds on the Cosmos Hub were lost as a result of the incident or the halt. The only affected assets originated from the Neutron chain exploit.
Third security scare in recent months
This is the third notable security-related event in the Cosmos ecosystem in a relatively short window. In August 2026, a vulnerability related to the Cosmos EVM affected multiple chains, though the Hub and ATOM were spared in that instance.
Governance attacks occupy an uncomfortable spot in blockchain security. They don’t exploit code bugs in the traditional sense. They exploit the rules of the system as designed, using legitimate governance mechanisms to authorize illegitimate actions.
In this case, the Neutron team halted operations quickly enough to contain the majority of exposed funds, and Cosmos Hub validators coordinated a response that recovered the ATOM portion. But the attacker still extracted a meaningful sum before anyone could react.
What this means for the Cosmos ecosystem
The validator response has drawn praise from security researchers for its effectiveness. Coordinating a network halt across a decentralized set of validators, then executing a token recovery on restart, is not a trivial operation.
For investors and developers in the Cosmos ecosystem, governance security is not a theoretical risk. An attacker turned $20,200 into access to $9.5 million in contracts.
Cross-chain composability also creates cross-chain risk exposure. A governance vulnerability on Neutron became a Cosmos Hub problem within hours, requiring the Hub to shut down entirely to prevent further damage.