⚠️ Exploit breakdown: Neutron governance attack
On Sept 22, an attacker used a @neutron_org governance proposal to take | Hanami
⚠️ Exploit breakdown: Neutron governance attack
On Sept 22, an attacker used a @neutron_org governance proposal to take admin on @astroport_fi and @dropdotmoney contracts, then moved funds. Notional loss $9.4M (~$1.96M already bridged out).
🔍 Root cause
Neutron’s wasmd lets chain governance execute MsgUpdateAdmin and rewrite a contract’s admin. App-level multisigs were not the final authority. Neutron chain governance sat above them and could take the contracts.
It also exposed a broken economic-security ratio. At incident-time prices, staked NTRN was worth about $113K, while that same governance power controlled ~$9.4M in contract assets. Decisive voting power was cheaper than the funds it secured.
🔗 Attack flow
1. Malicious proposal
Proposal #9, “AIATO: AI Agent Takeover”: https://neutron.celat.one/neutron-1/proposals/9
Sold as an AI governance research experiment. The payload was 11 MsgUpdateAdmin messages. Expedited process: 3-day vote, 67% threshold, 1M NTRN deposit.
2. Cheap votes
~$113K of staked NTRN was guarding ~$9.4M. The attacker first voted with ~100 NTRN, then 11 minutes before tally bought 31.62M NTRN with $20,199 USDC and delegated it.
3. Drain
One hour before voting closed, they uploaded code_id 5399 with a malicious withdraw_all { recipient } entrypoint. Within 24 minutes of execution they ran MsgMigrateContract ({"migrate_to_v2":{}}) on 10 contracts and called withdraw_all on each.
📌 Attacker addresses
Neutron:
neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605
Cosmos Hub:
cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n
Noble / Axelar / dYdX / Osmosis — same private key:
noble1dd25c4… / axelar1dd25c4… / dydx1dd25c4… / osmo1dd25c4…
Ethereum:
0xe149310eB8b1b3D9C471CcD81819D393621fBA5c
0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54