A malicious proposal exploited Neutron's governance process, granting the attacker admin control over smart contracts including Astroport and Drop Money, enabling asset drainage. Cosmos Hub validators coordinated a security halt to restrict stolen ATOM movement, and block production has since resumed as the ecosystem investigates the incident.
A Neutron protocol exploit enabled attackers to gain admin control over smart contracts, including those of Astroport and Drop Money, and drain assets through a malicious governance proposal. The Cosmos ecosystem coordinated a security response by halting affected networks and restricting stolen asset movement, with Cosmos Hub resuming normal operations after the incident.
Neutron protocol was exploited through a malicious governance proposal that granted attackers admin control over smart contracts including Astroport and Drop, allowing asset drainage. Cosmos Hub and other validators coordinated a security halt to contain damage, and block production has since resumed while investigation into the full scope continues.
A governance exploit on the Neutron blockchain on September 22, 2026 resulted in approximately $9.4M being drained from smart contracts. An attacker purchased voting power for $20K, manipulated a governance proposal to change contract admins, and migrated contracts to steal funds. The attack exploited the chain's continued governance authority despite being in wind-down since March.
A user reports that $20,199 in purchases influenced votes that depleted liquidity from Astroport and Drop platforms.