Astroport Reports Attack on Neutron Chain, Possible Unauthorized Access to Contract Admin Rights
Cosmos ecosystem exchange Astroport stated that an attack occurred on the Neutron chain, which may have led to unauthorized access to its contract admin rights. Neutron has suspended on-chain activities for investigation, and Astroport advises users to withdraw funds from all liquidity pools on the chain immediately.
Neutron confirmed that the attack targeting Astroport led to a chain halt to prevent further losses, with the investigation being community-led. Cosmos Hub validators temporarily halted the network to limit losses from governance vulnerabilities affecting ATOM, stating that the Hub itself was not impacted, and they are identifying and isolating related wallets before deciding on further actions.
The Terra Phoenix Foundation also warned that Astroport on Neutron may still be under attack, advising Terra users to withdraw liquidity tokens from Astroport as a precaution. Astroport's deployment is not limited to Neutron, so the withdrawal scope is defined as all on-chain liquidity pools, rather than a single chain.
Neutron has been in long-term maintenance since March this year, with multiple products gradually shutting down; it had previously paused order book functions due to a vulnerability disclosure. On January 13, 2026, the chain also halted at block 18906878 due to a non-deterministic query from the built-in oracle Slinky, with validators instructed to pause nodes while waiting for upgrades.
On July 30, 2024, the IBC-Hooks vulnerability on Terra was exploited, leading to the minting of approximately 53.7 million ASTRO tokens, of which about 33.77 million were transferred to Neutron and exchanged for approximately $136,000 USDC. At that time, Terra halted the chain to patch the issue, and the attackers' holdings on Neutron were temporarily transferred to the Astroport treasury, with the Terra address blacklisted.
The incident has triggered an exodus. Buyers have not formed yet, while sellers include liquidity providers and cross-chain holdings. Funds are flowing from Astroport pools to various chain wallets and trading venues; the beneficiaries are LPs who can withdraw first, while the pressured parties are the pricing of ASTRO, NTRN, and related pools, as well as ATOM cross-chain positions relying on Neutron governance and IBC channels. During the chain halt, not all redemptions can be completed, and the withdrawal window depends on when block production resumes.
Source: Public Information
ABAB AI Insight
Astroport is not the first to face issues with admin rights and cross-chain modules. After the IBC-Hooks patch was rolled back on Terra in 2024, attackers minted ASTRO out of thin air and bridged it to Neutron for sale, after which the team established a security sub-DAO and reclaimed permissions. The current statement indicates that "admin rights may have been stolen," and the chain halt occurred after the loss of control over permissions, suggesting that the emergency switch still lies with the chain-level validators, not within the application contract itself. Neutron announced long-term maintenance and product shutdowns in March, with public infrastructure handed over to external operations, and security incidents occurring on a contracting application chain.
The capital path indicates that governance rights precede financial rights. Once the admin is compromised, theoretically, parameters can be changed, contracts migrated, or controllable assets withdrawn; validators halting the chain effectively reclaim block production rights back to the node set, using time to isolate wallets. The Cosmos Hub separately halted the network for ATOM losses, which means cross-chain governance is transferring losses from the application chain back to the parent chain. Funds are first halted in blocks, and then community votes will decide whether to confiscate, roll back, or release.
This mirrors the IBC incidents of the same combination in 2024, as well as the historical precedents of "halt the chain first, then patch, then govern" seen in Terra, Secret, and Osmosis. The industry position is that maintenance-phase application chains are layered over cross-chain DEXs: the expansion phase is over, and control remains with validators and admin multisigs, with the transformation not yet completed. A chain that has announced maintenance still hosts liquidity from other chains, treating outdated infrastructure as a financial vault.
Structural changes represent the risk spillover after the failure of industrial chain reconstruction. Application chains delegate settlement to smart contracts, while the final brake is left to validators; once admin keys are compromised, the brake can only stop the entire chain. The mechanism is that cross-chain liquidity amplifies single-point permissions into multi-chain runs on liquidity, with the parent chain halting again to protect its native currency, transferring losses from DEX pools to ATOM holdings. Anyone who still places liquidity in cross-chain pools with admins is effectively market-making for others' governance vulnerabilities.
ABAB News · Cognitive Laws
- Admin rights are taken before the money in the pool.
- Halting the chain saves governance, not the assets that have already exited.
- A chain under maintenance can still transmit risks back to the parent chain.