Governance Attack Siphons $4.4 Million in Digital Assets
A targeted governance attack on a decentralized protocol has resulted in the extraction of $4.4 million in digital assets, highlighting vulnerabilities in expedited on-chain voting systems. The exploit centered specifically on the Neutron protocol, an interoperable network which operates within the broader Cosmos ecosystem. This manipulation ultimately put nearly double the extracted amount at risk before network operations were deliberately halted to contain the damage.
Mechanics of the Exploit
The perpetrator carefully orchestrated the attack by systematically abusing the protocol's decentralized governance structure. Initially, the malicious actor spent 20,199 USDC to acquire a position in NTRN, the native token utilized by the Neutron network. These acquired tokens were then deployed strategically to manipulate an active on-chain vote without alerting other network participants early in the process.
The malicious proposal in question was submitted using the network's expedited three-day governance track. According to information noted by Chain, the proposal successfully passed on Monday at 10:24 p.m. ET, securing 82% support from the participating voting weight. The decisive maneuver occurred exactly 12 minutes before the voting window officially closed. At this final moment, the attacker staked 31.6 million NTRN. This late-stage capital deployment overwhelmed the governance system, guaranteeing the passage of the malicious proposal and granting the attacker system authorization to drain targeted smart contracts on the network.

Financial Impact and Paused Assets
Following the successful governance manipulation, the attacker immediately targeted two specific decentralized applications built natively on the Neutron network. Smart contracts valued at $4.9 million were systematically drained from Astroport, while another $4.4 million was siphoned from Drop.
Despite the significant sums compromised by the illicit proposal, the attacker did not successfully withdraw the entirety of the vulnerable capital. The thief extracted roughly 20% of the funds that were initially exposed to the exploit. Because administrators quickly paused the Neutron network in response to the governance breach, further illicit withdrawals were effectively halted. This emergency pause mechanism resulted in an estimated $5 million in digital assets becoming trapped, preventing the attacker from fully cashing out the compromised smart contracts.
The total scope of the vulnerability extended well beyond the successfully extracted $4.4 million. Reports citing Foresight News and ME News indicate that the initial losses, or the total value of assets exposed during the incident, were valued between $9.4 million and $9.5 million. The swift pause of the network ultimately limited the extraction to a fraction of the total at-risk capital, leaving millions secured but temporarily immobilized.


