FacebookTwitterLinkedInTelegramCopy LinkEmail
Blockchain

How Cosmos Hub Stopped and Restarted to Seize Stolen ATOM

How Cosmos Hub Stopped and Restarted to Seize Stolen ATOM

Cosmos Hub resumed after an almost 25-hour halt with 1,227,121 ATOM moved from an attacker-linked address into recovery custody. The action may help Neutron victims, while showing that blockchain finality depends on more than a transaction reaching the chain.

The Cosmos Hub’s incident update says its network was not exploited. Stolen assets arrived from Neutron via IBC; Hub validators then paused their own chain and restarted it with a limited change affecting one account.

Cosmos recovery: the record

Network actionBlock production stopped, then resumed on Gaia v28.3.0.
State change1,227,121 ATOM moved from one account to recovery custody.
Recovery custodyA named 4-of-6 multisig holds the secured ATOM.
Important limitA later THORChain refund fell outside the first sweep.

Three powers people confuse in a blockchain emergency

A blockchain can halt block production when enough validators stop signing transactions, pausing normal network activity.

1. Stopping block production

Validators produce and confirm new blocks. On Cosmos Hub, the CometBFT consensus engine records blocks with agreement from at least two-thirds of validator voting power. When enough operators stop signing, ordinary transfers and other changes cannot settle on that chain. This is a liveness problem: the network is still there, but it is temporarily unable to progress.

2. Changing state at the restart

A halt alone does not move a coin. Cosmos Hub validators restarted on Gaia v28.3.0 with a one-time state change at block height 33,086,741, before further transactions were processed. It moved the remaining balance from one attacker-linked address to a 4-of-6 recovery multisig.

Cosmos Hub said the patched binary touched no other balances, delegations or user funds. The action did not use the attacker’s private key and did not reverse the Neutron exploit. Validators agreed to run updated code, and the restarted network accepted the altered Hub state. The Cosmos SDK supports state migrations during upgrades; the important point is that the ability becomes meaningful only when validator operators coordinate around it.

3. Holding recovered assets

The state change did not send the ATOM to a single company wallet. The recovery address is controlled by Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu, with four signatures needed to move the funds. Cosmos Hub says Neutron contributors and affected protocols are working out a recovery plan.

These are separate powers. A validator set can stop blocks without changing an account. It can agree to a targeted state change without deciding how recovered assets should ultimately be distributed. Treating all three as a simple “wallet freeze” hides the safeguards and the risks involved.

The halt stopped Cosmos Hub, not every settlement path

The most useful part of the incident is also the part that makes the recovery less tidy. The 1,227,121 ATOM sweep covered the balance that was present in the attacker-linked address at the halted height. It could not include assets that reached that address afterward.

Unchained and CryptoSlate reported that 168,991 ATOM from an unfilled THORChain swap returned to the address shortly after the restart. The refund arrived after the one-time change had already executed.

IBC had moved stolen ATOM from Neutron to Cosmos Hub, while THORChain created a separate settlement path. The episode shows why recovery teams must map pending swaps, bridge transfers, wrapped tokens and exchange deposits alongside the balance visible on the chain they control. Halting one network does not cancel activity already pending elsewhere.

Why this differs from an exchange freeze
An exchange can suspend withdrawals or change balances inside its own system during a security event. The reports around Bitget-linked wallet movements concerned exchange infrastructure; an exchange cannot independently rewrite another public chain. Cosmos Hub paused its own service and changed its own state through validator coordination.

Four checks before trusting a recovery

  1. Who can stop the network? Look at voting-power concentration, not only the number of validators.
  2. What exactly changed? The network should disclose the affected account, code version, restart height and scope of the patch.
  3. Who holds the recovered assets? Readers should be able to identify the signers, signature threshold and the process for distributing funds.
  4. What remains outside the intervention? Check cross-chain transfers, pending swaps and off-chain destinations before calling a recovery complete.

A chain without a workable response can leave victims with no recovery route. One with wide, undisclosed emergency powers gives users less certainty about completed transactions. The useful standard is narrower: emergency authority should have a public trigger, a defined scope and an auditable record.

What Cosmos has shown, and what it has not yet settled

Confirmed by the Hub update
Still unresolved
Cosmos Hub was not the exploited network, and its patched restart changed one named account.
The final allocation of the multisig’s ATOM to affected Neutron users and protocols.
The recovery address and six signers are public, with four signatures required.
The complete accounting of funds that moved through external settlement paths.
The initial sweep was limited to the account balance at the halted height.
Neutron’s full post-mortem and the final remediation steps for the exploited contracts.

Cosmos disclosed enough information to examine the scope of its intervention: the affected account, the code version, the restart height, the recovery address and the signers. The remaining test is whether the recovery plan provides the same clarity for victims whose assets are not in that multisig.

Emergency action can protect users after an exploit. Its authority, code and boundaries should be visible before a crisis forces the network to use them. That is the lasting lesson from the ATOM recovery: finality carries more weight when its exceptions are understood in advance.


This article is provided for informational purposes only and does not constitute financial or investment advice. Incident reporting and recovery plans can change as further technical and governance updates are published.

Author

Reporter at Coindoo

Alexander Zdravkov is a market analyst and crypto journalist with interests in economics, broader financial markets and digital assets. His journey into crypto began more than four years ago, driven by a fascination with the rapid evolution of blockchain technology and the transformative potential of decentralized finance. He began analyzing market cycles and identifying emerging trends before they reach the mainstream. He holds a degree in International Relations - a background that helped shape his broader perspective on global economics, geopolitics, and the interconnected nature of modern financial markets. Whether covering the latest developments in the crypto sector or exploring broader macroeconomic themes, Alexander focuses on giving readers context rather than simply repeating headlines. During his career, he has authored more than 5,000 articles covering cryptocurrencies, traditional finance, and global market developments. His work spans everything from Bitcoin and altcoins to macroeconomic trends influencing risk assets worldwide.

Learn more about crypto and blockchain technology.

Glossary