BTC $83,084.50 +0.17%
ETH $2,665.92 +0.86%
BNB $757.62 -1.02%
XRP $1.48 +0.24%
SOL $117.34 -0.88%
TRX $0.3340 +0.17%
DOGE $0.0930 +0.24%
ADA $0.2424 -0.64%
BCH $306.30 -2.66%
LINK $14.71 +7.09%
HYPE $87.08 -2.05%
AAVE $150.21 +0.98%
SUI $1.11 -7.10%
XLM $0.2232 +7.10%
ZEC $1,377.83 -11.09%
AAPL $337.28 -0.90%
AMZN $245.71 -1.29%
GOOGL $341.21 -0.12%
MSFT $506.94 -1.95%
META $710.84 -2.99%
NVDA $228.11 +1.78%
TSLA $355.83 -3.78%
SNDK $1,687.40 -2.34%
INTC $114.23 -3.94%
SPCX $145.61 -2.26%
MU $1,046.28 -1.60%
AMD $603.50 -1.95%
BTC $83,084.50 +0.17%
ETH $2,665.92 +0.86%
BNB $757.62 -1.02%
XRP $1.48 +0.24%
SOL $117.34 -0.88%
TRX $0.3340 +0.17%
DOGE $0.0930 +0.24%
ADA $0.2424 -0.64%
BCH $306.30 -2.66%
LINK $14.71 +7.09%
HYPE $87.08 -2.05%
AAVE $150.21 +0.98%
SUI $1.11 -7.10%
XLM $0.2232 +7.10%
ZEC $1,377.83 -11.09%
AAPL $337.28 -0.90%
AMZN $245.71 -1.29%
GOOGL $341.21 -0.12%
MSFT $506.94 -1.95%
META $710.84 -2.99%
NVDA $228.11 +1.78%
TSLA $355.83 -3.78%
SNDK $1,687.40 -2.34%
INTC $114.23 -3.94%
SPCX $145.61 -2.26%
MU $1,046.28 -1.60%
AMD $603.50 -1.95%

recover

All
Article
Flash

Cosmos Hub: 1.227 million ATOM has been recovered from the Neutron attack case, with funds temporarily stored at a 4/6 multi-signature address

Cosmos Labs disclosed that on September 22, Neutron encountered a governance attack that led to the theft of liquidity from protocols such as Astroport, with approximately 1.73 million ATOM subsequently transferred by the attacker to Cosmos Hub. The Cosmos Hub itself was not attacked, and user funds were not affected. To prevent the stolen ATOM from being transferred out, Hub validators temporarily paused the network for about 24.5 hours and resumed block production on September 23 based on the patched Gaia v28.3.0.Cosmos Labs stated that during the pause, 1.227 million ATOM remained in the attacker's Hub address. When the network was restored, these were transferred to a 4/6 multi-signature address composed of Nansen, Keplr, Enigma, Silknodes, Kiln, and Polkachu through a one-time change. Previously, about 500,000 ATOM had been exchanged for ETH via THORChain and could not be recovered; another 169,000 ATOM entered the attacker's address after the network was restored due to THORChain refunds and were sold after being transferred to Osmosis. The current multi-signature address holds approximately 1.227 million ATOM, which can only be returned after authorization from a Cosmos Hub governance proposal. The related funds will not be staked, lent, or traded. The Neutron team expects to submit a recovery plan and related governance proposals next week.

first_img Bitget updates on the security incident progress: the stolen amount is revised to 387.5 million USD, and the withdrawal recovery time will be announced before 12 PM tomorrow

Bitget TradFi Chief Growth Officer Xie Jiayin issued an update on the platform's security incident, stating that the withdrawal time will be announced before noon tomorrow. The security team has identified the hacker's attack path and methods, and has grasped the details of how the attacker bypassed security measures, coming very close to tracing the source of the attack. The incident investigation by third-party security teams Mandiant and SlowMist is still ongoing, with a detailed report pending from the security team.On-chain tracking confirms that approximately $387.5 million has been transferred to the hacker's address, previously estimated at $351.6 million. This revision includes ZEC and TRX, and no other unauthorized transfers have been found. Xie Jiayin stated that the stolen funds at the platform level will be fully covered by the Bitget User Protection Fund, ensuring that user assets are not subject to any losses.Bitget has officially launched a fund recovery bounty program, offering a 5% bounty for voluntarily freezing the attacker’s funds and a 5% bounty for voluntarily recovering funds. The bounty also applies to assistance already provided. The platform has published the attacker's address, a real-time tracking dashboard, and a submission portal, with relevant information also available for submission through Bybit's Lazarus bounty platform.

first_img Cronos rolled back the blockchain to recover 111 million USD in stolen funds

Cronos confirmed in a post-mortem report that the attack on the lending platform Tectonic on August 30 involved $120.4 million in borrowing activities. The validators made the "difficult decision" to roll back the on-chain history, successfully recovering approximately $111.2 million (about 92% of the affected funds), while about $9.19 million flowed out before the network was paused and could not be recovered. The attacker leveraged weak DEX liquidity to inflate the price of Tectonic token TONIC by about 100 times within minutes and borrowed $120.4 million through a single transaction across nine markets. The validators paused the network about two hours later, restoring the chain to the last block before the suspicious activity, with block production resuming approximately 11 hours after the attack. The rollback involved reversing 1 hour and 54 minutes of on-chain history, totaling 10,961 blocks, with all transactions within that window being canceled, regardless of whether they were involved in the attack. Cronos stated that the alternative would have been to restart the network without restoring the previous state, which would have left the stolen assets in the hands of the attacker. This rollback closely followed Harmony's announcement of a similar plan, while Flow abandoned its rollback proposal last December due to community opposition. The validator cap for Cronos is 100, which facilitated quick coordination for the pause and restart, but also indicated that the network's finality in emergencies depends on validator consensus.
app_icon
ChainCatcher Building the Web3 world with innovations.