Cosmos Hub validators stopped the network for nearly 25 hours to block $2.2 million in stolen ATOM after a governance attack on Neutron. Still, over 169,000 ATOM got away, raising new doubts about cross-chain security and how much can really be recovered.
Cosmos Hub's emergency shutdown to stop stolen funds showed both what on-chain action can do and where it falls short. After a governance exploit on Neutron let an attacker take over key smart contracts and drain millions, Cosmos Hub validators made a rare move. They halted block production for almost 25 hours. The goal was to freeze $2.2 million in ATOM before it could be moved deeper into the Cosmos ecosystem.
Network freeze and asset sweep
The halt started after the stolen Neutron funds were bridged onto Cosmos Hub. Validators paused the network and then ran a targeted upgrade at block 33,086,741. When the network restarted, the first block swept 1,227,121.37 ATOM-about $2.2 million at the time-from an address tied to the attacker into a recovery wallet. Cosmos Hub said its own protocol was not breached, but the halt was needed to stop more compromised assets from moving out of Neutron. Official updates stressed that the pause was a defensive step to contain losses and isolate affected wallets, not a reaction to a direct attack on Cosmos Hub itself.
Cosmos Hub validators independently halted the network to limit the movement of stolen ATOM and give exchanges time to act, confirming that the Hub itself was not compromised.
The recovered tokens are now in a community validator multisig. Cosmos Hub validators, Neutron participants, and affected protocols are working out how to return the funds to their owners. The quick action showed how much power validator governance has, but also how complicated cross-chain asset flows can get. Once assets move between blockchains, it's hard to contain an exploit. Independent reports put the amount swept at about 1.2 million ATOM, with the dollar value shifting between $2.1 million and $2.2 million depending on the market at the time.
How the exploit unfolded
The attack started when someone gathered enough NTRN, Neutron's governance token, to push through a fast-track proposal. This gave them admin rights over 11 smart contracts, including ones for Astroport and Drop. With control, the attacker switched the contracts to malicious code and made unauthorized withdrawals. Independent breakdowns say the attacker took about $4.9 million from Astroport and $4.4 million from Drop. The total impact hit several assets and protocols. Some estimates, like those reported earlier, put total losses closer to $9.3 million.
Neutron's own rate limits and a later network halt stopped some assets from leaving. More than $1.6 million in USDC and large amounts of NTRN and ASTRO were reportedly protected. Still, about 70% of the stolen ATOM made it onto Cosmos Hub, which led to the network-wide freeze and recovery. As of the latest updates, the attacker's wallet still held big on-chain balances: around 1.67 million USDC, 96.2 million NTRN, and 370 million ASTRO, according to independent monitoring.
The Cosmos Hub operates on a proof-of-stake consensus mechanism, with validator governance enabling rapid network interventions. This structure allows validators to coordinate emergency actions, such as halts and targeted upgrades, to protect user assets in the event of cross-chain exploits.
169,000 ATOM escape recovery
Even with the sweep, not all funds were caught. Crypto analyst Rarma pointed out that 168,990.9 ATOM landed in the attacker's address seven blocks after the restart, coming from a THORChain refund. These tokens sat untouched for almost six hours, then were sent to Osmosis and sold in batches for about 266,841 USDC. Much of that was later swapped for Ethereum. This late-arriving ATOM was not part of the first recovery transaction. Cosmos Hub has not explained why this later transfer was allowed or if more restrictions were considered for funds reaching the address after the sweep.
The attacker had earlier tried to move 500,000 ATOM, but the transaction failed due to not enough funds in the wallet. Still, the transaction was included in a block and the fee was paid, showing the attacker's address could still send inter-blockchain transfers after the restart. This shows how hard it is to fully contain cross-chain exploits, even with strong network-level action.
Next steps for Neutron and Cosmos
Most of the recovered ATOM is now under community control. Cosmos Hub says a forum update will give more details on the secured assets. Neutron contributors have built a new binary to restore affected contracts, tighten governance, and move any remaining attacker-controlled assets into a validator multisig. The process for returning assets is still being worked out. The plan is to send recovered funds back to the original contracts and users once Neutron resumes block production. A full post-mortem will come after the chain is back online.
So far, Cosmos Hub's move has secured most-but not all-of the ATOM stolen in the Neutron exploit. The incident forced both networks to face the risks of cross-chain operations and governance, and the real limits of even the strongest recovery efforts. For U.S. users and developers, this is a clear warning: validator-driven actions can reduce damage, but they can't guarantee full recovery when assets move quickly across connected blockchains.
At the time Cosmos Hub restarted, 1,227,121.37 ATOM (about $2.2 million) were swept into a recovery address. Another 168,990.9 ATOM escaped and were later sold for about 266,841 USDC. The original exploit on Neutron hit contracts for protocols like Astroport and Drop, with total losses estimated between $4.4 million and $9.3 million depending on the source. Neutron's rate limits and halt protected over $1.6 million in USDC and large amounts of NTRN and ASTRO, but most of the stolen ATOM had already crossed to Cosmos Hub before the freeze.
Cross-chain governance attacks like the one on Neutron show a core risk in blockchain interoperability. Once assets move between networks, freezing, recovering, or returning funds depends on the technical and governance tools of each chain. Validator-driven halts and asset sweeps can work right after an exploit, but attackers may still find ways to move or cash out funds, especially if refunds or delayed transactions arrive after recovery steps are taken. For anyone using or building across multiple blockchains, knowing these limits is key to managing risk in a more connected crypto world.