• 4 mins read
  • Published

Neutron DAO admin shakeup happens as $9 million crypto loss hits Astroport and Drop

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Neutron DAO admin shakeup happens as $9 million crypto loss hits Astroport and Drop EgonCoin © egoncoin.com
Neutron DAO admin shakeup happens as $9 million crypto loss hits Astroport and Drop © egoncoin.com

Neutron DAO pushed through 11 contract admin changes just as SlowMist flagged a $9.3 million loss at Astroport and Drop. The overlap is raising new alarms about how much power protocol governance really holds-and what it means for user risk.

On September 22, Neutron DAO voters approved a major overhaul of contract administration across the network. At the same time, security tracker SlowMist reported that Astroport and Drop lost a combined $9.3 million. The overlap has put protocol governance under a harsh spotlight. Many users may not realize just how much control a DAO can have over the apps they use every day.

Governance moves and security fallout

Neutron's proposal #9, called "AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration," passed with 11 "Update Admin" actions logged on the chain explorer. These moves let the DAO swap out administrators for several contracts. Neutron's own governance docs call this the network's highest authority. Even though users see Astroport and Drop as separate services, their contracts are still tied to network-level decisions. The Cosmos Hub network was halted for more than 24 hours to contain the fallout. That shows how serious the governance event was-and how wide its impact spread.

The Neutron incident is classified as a governance attack, not a protocol bug-voting enabled admin changes that led to the exposure of Astroport and Drop contracts.

GoPlus Security

That same day, SlowMist tracked $4.9 million lost at Astroport and $4.4 million at Drop. The two incidents were logged separately but happened alongside the DAO's admin shakeup. This shows how governance can trigger problems that reach far beyond a single app. Independent analysis says the attack started at 02:38:30 UTC on September 22, 2026. In just 24 minutes, 10 contracts were drained. That speed shows how fast governance-enabled exploits can hit.

Losses still unsettled, assets partly contained

No one knows yet how much money is truly gone. TokenPost and other sources point out that some of the affected assets were frozen by the network halt, not outright stolen. So the $9.3 million figure is only a first estimate, not a final loss. It matters whether assets were just "exposed" or actually taken, since recovery efforts and technical fixes could still change the outcome.

Whether users get their money back depends on how withdrawals, cross-network moves, and asset freezes play out. For now, the case shows how hard it is to track losses in decentralized systems. Governance actions and technical responses can collide in ways no one expects. GoPlus Security warned that Neutron "may have exposed admin control of Astroport contracts" and told users to pull their liquidity from Astroport on all chains until further notice.

Governance attacks differ from traditional protocol bugs by leveraging legitimate voting mechanisms to alter contract administration. This incident highlights the importance of understanding DAO powers and the risks they pose to both users and applications.

CoinDeskTier-1 Outlet

DAO power and user risk

Neutron's governance lets its DAO make contract-level changes, even for contracts that run third-party apps. That means users of Astroport or Drop can face risks from decisions made at the network level, not just inside the app. Proposal #9 covered 11 contracts, showing just how broad these powers are.

Neutron is not alone. As reported earlier, protocol-level flaws and admin controls have caused big losses on other networks too. Users often don't see these risks from the front-end or in the docs.

Money lost and the road to recovery

SlowMist's $9.3 million estimate shows the immediate hit across Astroport and Drop as of September 22. The real loss or recovery will depend on what happens to assets stuck during the network halt, how well recovery efforts work, and whether users or defenders can get funds back. For now, this is a clear case of how protocol governance and security events can collide-with real fallout for users and apps.

When a DAO controls contract admin keys, the line between network governance and app-level risk gets blurry. Users may not know their assets depend on decisions made far upstream from the services they use. This makes it harder to judge risk or respond to incidents, especially when governance moves and security problems hit at the same time.

In decentralized finance, protocol governance is often sold as a way to give power to the community and align incentives. But this incident shows that the same tools can open new doors for loss-especially when admin powers are wide and users don't fully understand them. Anyone using DAO-run networks needs to know who holds contract admin rights and how those powers are used. That's not just a technical detail. It's a core part of managing risk.

Related articles