Neutron Governance Takeover
An attacker bought cheap voting power to pass a malicious Neutron governance proposal, seizing admin rights over ten Astroport and Drop contracts and draining about $9.4 million in 24 minutes.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
An attacker bought cheap voting power to pass a malicious Neutron governance proposal, seizing admin rights over ten Astroport and Drop contracts and draining about $9.4 million in 24 minutes.
Incident
- Victim: Neutron
- Date (UTC): 2026-09-22
- Estimated loss: $9.4M
- Chain(s): Neutron
- Attack type: governance
- Funds status: stolen
Recommended actions
- Revoke token approvals granted to Neutron contracts until the project confirms they are safe
- Integrators: pause or delist affected assets and monitor for attacker fund movements
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/neutron-2026. Primary sources: https://en.cryptonomist.ch/2026/09/23/neutron-governance-attack-exploit/ ; https://forum.cosmos.network/t/neutron-governance-attack-cosmos-hub-response-and-recovery-update/17369 ; https://thecurrencyanalytics.com/altcoins/cosmos-hub-goes-dark-for-24-hours-after-9-5-million-neutron-governance-breach-296455.
References
- https://www.blockchainbreaches.com/en/breaches/neutron-2026
- https://en.cryptonomist.ch/2026/09/23/neutron-governance-attack-exploit/
- https://forum.cosmos.network/t/neutron-governance-attack-cosmos-hub-response-and-recovery-update/17369
- https://thecurrencyanalytics.com/altcoins/cosmos-hub-goes-dark-for-24-hours-after-9-5-million-neutron-governance-breach-296455
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-22 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0229/signed.txt | gpg --verify