n
news9/23news⚠️ Exploit breakdown: Neutron governance attack On Sept 22, an attacker used a @neutron_org governance proposal to take admin on @astroport_fi and @dropdotmoney contracts, then moved funds. Notional loss $9.4M (~$1.96M already bridged out). 🔍 Root cause Neutron’s wasmd lets chain governance execute MsgUpdateAdmin and rewrite a contract’s admin. App-level multisigs were not the final authority. Neutron chain governance sat above them and could take the contracts. It also exposed a broken economic-security ratio. At incident-time prices, staked NTRN was worth about $113K, while that same governance power controlled ~$9.4M in contract assets. Decisive voting power was cheaper than the funds it secured. 🔗 Attack flow 1. Malicious proposal Proposal #9, “AIATO: AI Agent Takeover”: https://neutron.celat.one/neutron-1/proposals/9 Sold as an AI governance research experiment. The payload was 11 MsgUpdateAdmin messages. Expedited process: 3-day vote, 67% threshold, 1M NTRN deposit. 2. Cheap votes ~$113K of staked NTRN was guarding ~$9.4M. The attacker first voted with ~100 NTRN, then 11 minutes before tally bought 31.62M NTRN with $20,199 USDC and delegated it. 3. Drain One hour before voting closed, they uploaded code_id 5399 with a malicious withdraw_all { recipient } entrypoint. Within 24 minutes of execution they ran MsgMigrateContract ({"migrate_to_v2":{}}) on 10 contracts and called withdraw_all on each. 📌 Attacker addresses Neutron: neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605 Cosmos Hub: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n Noble / Axelar / dYdX / Osmosis — same private key: noble1dd25c4… / axelar1dd25c4… / dydx1dd25c4… / osmo1dd25c4… Ethereum: 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c 0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54
85/100·AShort+4