‹ BackNewsAtom

Atom

Cosmos Hub’s 25-Hour Halt Shows Where Blockchain Consensus Actually Breaks
Cosmos
2026-09-29 12:30:00

Why Cosmos Hub Stopped Producing Blocks for 25 Hours

Cosmos Hub halted block production on Sept. 22 after validators representing more than one-third of total voting power stopped participating, freezing the chain at height 33,086,740. The trigger did not originate on Cosmos Hub itself. The sequence began on Neutron, where a governance proposal titled AIATO: AI Agent Takeover was exploited through chain-level governance privileges in the wasmd framework, allowing attackers to reassign contract admin rights for apps including Astroport and Drop. Before Neutron stopped running, Cosmos Labs said the attackers had already moved assets across several networks, including roughly 1.7 million ATOM into Cosmos Hub, where the funds began moving through interchain liquidity routes. To prevent the remaining ATOM from leaving, some Cosmos Hub validators shut down their nodes. That pushed the network below the threshold needed to keep CometBFT consensus live. About four hours later, validators received a recovery plan built around a one-time state change. Cosmos Labs then prepared and tested a Gaia v28.3.0 patch. The patch moved 1,227,121 ATOM from the attacker address into a 4-of-6 multisig controlled by Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu. Once validators representing more than 67% of voting power had installed the software, Cosmos Hub coordinated a restart at 12:00 UTC on Sept. 23. Roughly six minutes later, the state change executed at block 33,086,741 and block production resumed.

220
Why Cosmos Hub Stopped Producing Blocks for 25 Hours
Cosmos Hub recovers 1.227 million ATOM from Neutron exploit, moves funds to 4-of-6 multisig
Cosmos Hub voters move to veto proposal seeking 1.2 million ATOM refund for Neutron attacker
1.227 Million ATOM Moved to 4-of-6 Multisig After Neutron Governance Attack
Binance spot data shows sharp swings as ATOM jumps 12.84% in 24 hours
Cosmos
2026-08-25 02:41:56

Cosmos EVM chains hit by attacks after public patch release sparks warning failures

A string of attacks has hit blockchains using the Cosmos EVM module, including MANTRA, TAC, KiiChain, and Nesa, with treasury-held protocol reserve tokens stolen and quickly sold on the market. The incidents were later linked by market participants to version v0.7.2 upgrade code published by Cosmos Labs on GitHub on Aug. 19. The release note itself said the version contained an important security fix and urged chains to upgrade through a coordinated process as soon as possible. The controversy centers on how the patch was handled. Critics said Cosmos Labs made the security fix public without privately warning downstream teams or issuing any mandatory upgrade notice to projects relying on the module. Developer @justde said the failure was not the existence of a vulnerability itself, but what happened after it became known: who got warned, who got patched, and whether customers or attackers moved first. KiiChain, one of the affected projects, said the incident could have been avoided and disclosed that the exploit required three upstream flaws in Cosmos EVM to be present at the same time. Nesa said on the night of Aug. 24 that it had detected malicious activity exploiting the Cosmos EVM vulnerability on its L1 and halted the chain while applying fixes and remediation measures. According to the report, its token had already dropped more than 94%, from $0.22 to $0.011. RootData data cited in the article also showed ATOM with an $800 million market capitalization, ranking 68th among tokens, down more than 95% from its peak.

640
Cosmos EVM chains hit by attacks after public patch release sparks warning failures
Intel opens part of its Atom processor technology to Rosaic Labs