Security1 publisher2 min readPublished
Neutron governance overrode Astroport and Drop multisigs in a $9.4 million theft
Astroport and Drop contracts lost about $9.4 million on September 22 after an attacker won a Neutron governance vote that reassigned their admins. GoPlus Security values the staked NTRN behind that vote at about $113,000, far below the assets it could hand over.
The Watch · Security desk

What happened
- An attacker used a Neutron governance proposal on September 22 to seize admin rights over Astroport and DropDotMoney contracts and drained about $9.4 million.
- The vehicle was Proposal #9, titled "AIATO: AI Agent Takeover," which was pitched to voters as an AI governance research experiment.
- The attacker bought 31.62 million NTRN 11 minutes before the vote tally to secure control of the outcome.
- Within 24 minutes of execution, 10 contracts were migrated and drained, with funds later spread across Neutron, Cosmos Hub, Noble, Axelar, dYdX, Osmosis and Ethereum addresses.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams deploying on a shared chain have to check which messages chain governance can execute against their contracts before treating their own multisig as the last word on admin rights.
- cost NTRN's market price, not the apps' own multisigs, set their cost of attack, with the backing stake worth about one eighty-third of the $9.4 million it controlled.
- constraint A token buy 11 minutes before the tally leaves little time for a counter-vote, so watching open proposals does little against late vote buying.
According to GoPlus Security, the theft ran through Neutron's own governance process [10]. Neutron is built on wasmd, and wasmd lets chain-level governance execute MsgUpdateAdmin, the message that rewrites a contract's administrator [3]. Astroport, a decentralized exchange, and DropDotMoney, a separate protocol on Neutron, relied on multisig wallets to guard their contracts [9][3]. A passed proposal outranked those wallets. Governance could reassign the admin at will, and here it did [3].
The price of that authority was low. GoPlus puts the staked NTRN securing Neutron governance at about $113,000 at the prices in place during the attack, against roughly $9.4 million in contract assets under the same vote [4]. The vote controlled about 83 times the value of the stake behind it [1]. GoPlus described the incident as a mismatch between what it costs to control a chain's governance and what that governance protects [2].
I'd rate exploitability high on any chain set up this way. The attacker needed no stolen key and no code flaw, only a proposal that passed and enough tokens at tally time [3][10].
About $1.96 million had been bridged out by the time GoPlus published [8]. That leaves roughly $7.44 million, about 79 percent of the loss, that had not crossed a bridge at that point [2][3]. Cryptonomist, which reported the breakdown, wrote that the gap suggests some assets may still be traceable, while also saying the bulk of the value had already moved [11].
The override permission comes from wasmd, per GoPlus [3]. Cryptonomist argues the exposure reaches any protocol where a small pool of staked tokens governs a much larger pool of locked value, since an attacker has every incentive to try once buying a swing vote costs less than the assets under it [12].
The public account is one firm's analysis relayed by one publication [2]. Several questions are still open: who the attacker is and whether they are tied to other incidents, what they paid for the NTRN, and whether Neutron has changed who can send MsgUpdateAdmin [2].
What to watch
- Any Neutron governance change that restricts chain-level MsgUpdateAdmin over deployed app contracts.
- Freezes or recoveries of the roughly $7.44 million that had not been bridged out when GoPlus published.
- Other wasmd-based chains disclosing whether their governance can reassign app contract admins, and how their staked value compares with the value it controls.