Cosmos Hub Halts Operations for 24 Hours Following Governance Attack on Neutron
Cosmos Hub validators halted block production on Tuesday due to a governance attack on the Neutron chain, which resulted in initial losses estimated at $9.5 million. The attacker managed to extract around 20% of the funds, with the remainder trapped on halted networks.
Block production resumed at 12:00 UTC on Wednesday after the Cosmos Hub was offline for more than 24 hours, having halted at block height 33086740. This incident marks the third security scare for the Cosmos ecosystem in recent months.
The governance attack involved a malicious proposal dubbed “AI Agent Takeover,” which allowed the attacker to gain control of two Neutron-based applications, Astroport and Drop. This enabled the extraction of assets worth $4.9 million and $4.4 million, respectively, with the attacker spending only $20,199 to acquire the necessary NTRN tokens for the vote.
In response to the attack, Neutron was paused, trapping approximately $5 million worth of assets. Cosmos Hub validators decided to halt operations to secure an additional 1.2 million ATOM (valued over $2.2 million) held in the attacker's address. The scheduled restart will include a queued refund of the trapped ATOM balance.
The hacker's Ethereum address currently holds $1.8 million, with another transaction worth over $300,000 pending on THORChain, which is expected to be refunded to the Cosmos Hub address upon restart.
This incident follows previous security concerns within the Cosmos ecosystem, including a bug in Cosmos Labs’ EVM module that led to protocol-level exploits across four blockchains and a separate exploit involving Osmosis.
FAQ
What caused the halt in operations for the Cosmos Hub?
The halt was caused by a governance attack on the Neutron chain, which resulted in significant financial losses and prompted validators to stop block production for security reasons.
How much was initially lost due to the governance attack?
Initial losses from the governance attack were estimated at $9.5 million, with the attacker managing to extract around 20% of the funds.
What was the malicious proposal that led to the attack?
The malicious proposal was dubbed 'AI Agent Takeover,' which allowed the attacker to gain control of two Neutron-based applications, Astroport and Drop, leading to the extraction of significant assets.
What actions were taken to secure the assets after the attack?
Cosmos Hub validators halted operations to secure an additional 1.2 million ATOM valued over $2.2 million held in the attacker's address and paused Neutron to trap approximately $5 million worth of assets.
What is the current status of the hacker's assets?
The hacker's Ethereum address currently holds $1.8 million, with another transaction worth over $300,000 pending on THORChain, which is expected to be refunded to the Cosmos Hub address upon restart.
Comments
Comments are moderated before publish.
No comments yet — be the first.