Ray Raspberry retweeted
Neutron / Astroport exploit: what happened when the Cosmos Hub restarted. The 1.2M cosmos:native sweep worked. The 168,990 ATOM THORChain refund didn't get caught. It landed on the attacker a minute after the restart, and he sold all of it for about 100 ETH. Correction first In my last post I said the refund couldn't move once it landed, because the Hub had blocked the attacker's address. That turned out to be wrong, it appears the developers of the hub failed to correctly block the attackers address, when they had a ~6 hour window to act. What worked The Hub restarted at 10:06 pm AEST on v28.3.0. In the first block (33,086,741), the upgrade moved 1,227,121.37 ATOM off the attacker's address to cosmos1z8pq5cn7tdrwwzlwm0e44fgq07e43ner6vph64. It's still there, untouched. That's about $2.2M kept from him. What didn't 10:07:38 pm, block 33,086,748. THORChain's vault sent the refund, 168,990.898794 ATOM, to the attacker's address. 10:09:29 pm, block 33,086,761. He signed a 500,000 ATOM IBC transfer to Osmosis. It was included in a block, he paid the fee, and his account sequence went from 8 to 9. It failed only because he asked for more than he had. That transaction should never have reached a block if the address block was working. 3:54:58 am, block 33,090,325. He tried again with the right amount. It went through. Where it went He sold it on Osmosis in chunks of about 20,000 ATOM between 3:58 and 4:48 am, for 266,841 USDC, an average of $1.58. 188,832 USDC went through Noble and Circle's CCTP to 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c and was swapped to $ETH within minutes. +70.84 ETH. 50,000 ATOM went to a new key first. 30,000 of it made a round trip Osmosis → Hub → Terra → Hub → Osmosis. He then sold it and sent 78,010 USDC through Axelar to a new wallet, 0x9bfcca13b4ac907433ac68766e96309ac867f819. 29.22 ETH, never sent. 53 minutes from the Hub to ETH. Root cause: two gaps The refund arrived after the sweep. The upgrade moved what was on the address at block 33,086,741. The refund came seven blocks later. THORChain had GAIA halted (HALTGAIACHAIN = 1), but signing for GAIA was never halted (HALTSIGNINGGAIA = 0). My reading is that the halt stops THORChain watching the Hub, not signing for it. The vault's refund went out as soon as the Hub produced blocks. THORNode still shows the refund as "not signed" because it can't see the Hub. The ante-handler block didn't reject him. A transaction the ante-handler rejects never reaches execution. His reached the bank module and paid a fee. I can't see the v28.3.0 code (only v28.0.0 is public), so I can't say why. The chain shows it wasn't enforced for his address on an IBC transfer. Both gaps were visible on-chain by 10:09 pm. The refund sat on his address for 5 hours 47 minutes before he moved it. Where the attacker's funds are now 0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54: 671.0 ETH 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c: 94.43 ETH 0x9bfcca13b4ac907433ac68766e96309ac867f819: 29.22 ETH New Cosmos-side addresses from last night: osmo1erq7tre6nk0jfx203z8ey75g4m7yfrckl3qx87 cosmos1erq7tre6nk0jfx203z8ey75g4m7yfrckh2nk3v terra1utez3t0nvg34d9xfswn8058kypney2c3pkx883 Worth taking from this A sweep in an upgrade handler only covers what's on the address at that block. Anything still in flight needs its own plan. Test an address block with a real transaction as well as a simulated one, and watch the account sequence right after restart. Halting a chain in THORChain doesn't stop outbound signing for that chain. @cosmoshub @THORChain @Osmosis_Zone @Neutron_org @astroport_fi
8
7
53
5,500
Ray Raspberry retweeted
Neutron / Astroport exploit, update. The attacker's 1,227,121 ATOM on the Cosmos Hub is being moved to a new multisig when the chain restarts. One more piece still needs dealing with after restart: a 168,990 ATOM refund on its way back to him. What's already on his address When the Hub halted at block 33,086,740, the attacker's address held 1,227,121.37 cosmos:native (~$2.22M). The new Hub binary does two things. The upgrade handler moves that balance to a new multisig, and the ante-handler blocks his address from signing anything. The refund nobody could see His last THORChain swap was 200,000 ATOM streamed into $ETH. Only 15.5% had filled when the Hub stopped. THORChain paid that part out as 19.92 ETH and closed the swap. The other 168,990.898794 ATOM is queued as a refund to his Hub address. His wallet shows nothing pending, and the swap looks finished once the ETH arrives. I found the refund by reading THORChain's outbound queue (thorchain-thornode-lb-1.thor…) directly and matching it on the swap's inbound hash: REFUND:02DABD55C0A3EBEA3271763484542CB59A22E968402F91690471B7D2589B04A7 168,990.898794 ATOM → cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n It's scheduled but not signed, and was still in the queue at 23:43 UTC on 22 Sep. It hasn't gone out because THORChain has GAIA halted (HALTGAIACHAIN = 1). When that lifts, the vault signs and the ATOM lands on the attacker's address. That will be after the Hub upgrade has already run, so the refund misses the multisig move. Can he get around the block? Before the restart I checked whether he has any other way to move funds from that address. He doesn't. It's a plain account with one key. No authz grants in either direction, no fee grants, no delegations, unbonding or rewards, not a validator, no contracts, gov deposits or IBC transfers. If that key can't sign, nothing moves. That's why the ante-handler block works here. What still needs doing after restart The 168,990 ATOM (~$306k) needs one of two things: a second sweep once it lands, or THORChain node operators holding or redirecting that outbound before they unhalt GAIA. The block stops him moving it. It still needs to be moved to the multisig. Totals at $1.81 ATOM 1,227,121.37 ATOM on the address → multisig at upgrade 168,990.90 ATOM refund → needs a sweep after restart 1,396,112.27 ATOM, about $2.53M, kept from the attacker.
8
15
91
15,458
It wasn't an exploit. @neutron_org Validators passed the prop. Two likely situations are: Validators understood the proposal (handing over admin control of contracts) and were indifferent or didn't read the substance of the proposal to begin with. Either way is negligence.
The Cosmos Hub validators have temporarily halted the network to mitigate ATOM losses from a governance exploit on @neutron_org. The Hub itself is not affected. The community is identifying and isolating wallets with impacted funds and will decide what to do with them before resuming operations. Please stay tuned for further updates.
6
2
32
3,304
Ray Raspberry retweeted
Oh, looks like the @OsmosisFdn exited their allBTC holdings to real BTC before halting the pool. Very nice of them! nitter.net/OsmosisFdn/status/1719… mintscan.io/osmosis/address/…
The Osmosis Fdn’s address for @WrappedBTC on @osmosis as a DAO member is osmo1xz85h2nvc5l5dxvjpajvdcnk4wq20nydzunvn2
2
2
16
2,391
Ray Raspberry retweeted
allBTC on @osmosiszone is 63.97% backed. There are 110.57094432 allBTC in circulation against 70.73128010 BTC of real collateral. The 39.83966422 BTC gap is nBTC issued by @nomicbtc, which has been halted since 7 September. The full trace follows, with sources for each step. Vulnerability github.com/nomic-io/nomic/bl… ibc_deliver calls Coin::<Nbtc>::mint(amount) twice for a single incoming deposit. The first result is consumed by burn_coins_execute; the second is credited to the destination as spendable nBTC. It is the only one of the 18 #[call] handlers in that file with two mint calls, and it performs no signer check on the crediting account. IBC_FEE_USATS = 1_000_000, so invoking it costs one satoshi. The code is unchanged on develop HEAD. Mint Nomic block 33,137,470, 25 June 2026 21:49:59 UTC tx BEE54496B351A018D092779FE6C833238E1CDF965FE9761A572934F37932E028 25 send_packet events, sequences 9286–9310, 162,602,409,537,873 usat each, totalling 40.65060238 nBTC. The block contains no transfer, coin_spent, coin_received or burn events. Signer: nomic1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8cgz4wt, which has signed two transactions — a probe on 23 June at 03:01:56, then this one. This is verifiable without a Nomic node. All 25 packets arrive on Osmosis block 64,910,685 over channel-6897, in six relayer transactions, at the same per-packet amount, from nomic1kq2rzz6fq2q7fsu75a9g7cpzjeanmk685ak9g7 to osmo1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vtzltn. Addresses The same 20-byte account ID appears on four chains: nomic1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8cgz4wt osmo1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vtzltn (15 txs, sequence 15) noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890 (2 txs) axelar1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8q788kq Ethereum beneficiary: 0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5 Drain, via Osmosis pool 1868 Pool 1868 is the allBTC transmuter, which exchanges 1:1 with no slippage. 64,911,162 · 21:59:14 — 1.0 nBTC to 1.0 WBTC.axl 64,911,346 · 22:02:46 — 7.0 nBTC to 7.0 WBTC.axl 64,911,801 · 22:11:27 — 8.0 WBTC.axl bridged (468D435D4705105362DB6BEABFB98852156998A1973CBAA146E1737AC637EE82) 64,911,856 · 22:12:35 — 10.0 nBTC to 10.0 WBTC.axl 64,911,947 · 22:14:21 — 1.5 WBTC.axl bridged (EF6FFD3034E32DC52B04262681E10311F1EBA626BA0CE7510992963387A30794) 64,912,704 · 22:28:53 — 0.29880120 WBTC.axl to 8.09767026 ETH.axl 64,912,733 · 22:29:53 — bridged (F879A15766BED480F913E74888F572574D88F603CE2EEC97E67946C2A4A1D1D7) 64,915,592 · 23:24:58 — 1.99940004 allBTC to 112,509.46 USDC, sent by IBC to Noble 65,121,991 · 28 Jun 18:33:44 — 6.16296736 WBTC.axl bridged (70DFD62F6DC370C25EDD726CF87BCDB3F668E9049AC88B46E6C7E15C0E182904) 66,554,379 · 17 Jul 22:44:35 — 22.65060847 nBTC to 22.65060846 allBTC The 22.65 allBTC is still in the wallet and has not moved since 17 July. @axelarr to Ethereum Four GMP transfers, each naming SquidRouter 0xce16F69375520ab01377ce7B88f5BA8C48F8D666 as destination with 0x8f36fd9f… encoded in the payload. Each executes as Axelar Gateway, SquidRouter, SquidMulticall, Uniswap V3 WBTC/WETH, WETH unwrap, then native ETH to the beneficiary. 0x75b42eceb283eaa88303d23bca8f9ccc6c5579cdfc1e8c757ea1e33118dd125b · blk 25,397,547 · 303.01315917 ETH 0xe051dc2bbb37b1510faecaeace9288ca5bc0deda9562bdfe164643d268e69236 · blk 25,397,562 · 57.09781972 ETH 0x3dc170230bbbaab36b0bbfb0201ba705d09448be9db973c3725a72577e54ae1a · blk 25,397,637 · 8.09751591 ETH 0x6426edf655e833c2544a5541faceadb22d8d7c9a758432b409932155b6b4148f · blk 25,417,983 · 232.39729801 ETH The ETH arrives through internal calls rather than ERC-20 transfers, so it does not appear in a token-transfer scan of the wallet. It shows up under debug_traceTransaction. @noble_xyz to Ethereum via Circle CCTP Noble 53,482,030 · 14003B7245C38C55778DA07C77AC123A69711AD95D264EC2F4DDA162985C0CD3 · DepositForBurn 56,254.663934 USDC, nonce 349050 Noble 53,482,093 · D8FFF6FD4538CA34B0F40AB842E1C67AF1590DA922AF93B29B0475C7C055FF99 · DepositForBurn 56,254.623933 USDC, nonce 349052 mint_recipient on both is 0x8f36fd9f…d2b5. Minted on Ethereum at blocks 25,397,917 and 25,397,924, then swapped through 1inch Fusion for 71.14822656 ETH at block 25,397,930. Destination The beneficiary received 671.75412248 ETH and sent 671.10 ETH to the Tornado Cash router 0xd90e2f925da726b50c4ed8d0fb90ad053324f31b in 34 deposits: 439.10 ETH on 25 June between 22:56 and 23:46, and 232.00 ETH on 28 June between 18:41 and 18:46. The remaining balance is 0.5753708194 ETH. Nothing has moved since 28 June. The wallet's only funding before the exploit was 0.03729586 ETH received on 22 June from an address-poisoning bot, followed 24 seconds later by a counterfeit token from a lookalike address. There is no exchange or mixer deposit into it. Reconciliation 40.65060238 nBTC minted, plus 0.00000612 left over from a legitimate test purchase on 23 June, gives 40.65060850 available. Against that, 18.00000000 was converted and bridged out, and 22.65060847 was converted to allBTC and left on Osmosis, totalling 40.65060847. The difference is 3 usat, or 0.000003 satoshi. Of the 18.0 converted: 15.66295187 went out as WBTC and returned 592.50827690 ETH; 0.29880120 became 8.09751591 ETH; 1.99940004 became 71.14822656 ETH through Noble; approximately 0.0388 was lost to slippage, relayer fees and gas. Halt Nomic stopped at block 34,837,131 on 7 September 15:30:21 UTC. That block contained one transaction with code=0, no validator updates and no end-block events. Consensus is at height 34,837,132, round 0, step 1, with no proposal. Bitcoin checkpointing stopped 23 hours 39 minutes earlier, while the chain was still producing blocks. The last checkpoint is Bitcoin block 965,798, txid 105f80d33d383667cf200a81cd1c0cf2ed829ba4f696e44b7d5c89e94262d705, confirmed 6 September 15:51:27, paying 0.74599951 BTC to bc1q9e3d4nca68wzh8j3gme7z7gatnrzrpgcflsu5tgeuh6g7svqykssqzxyfe. That output is unspent and Bitcoin is now 316 blocks past it. Fee exhaustion does not explain this. The median observed checkpoint fee is 3,598 sat and the maximum ever paid is 15,064 sat. The final reserve UTXO holds 74,599,951 sat, enough for roughly 17,400 checkpoints. Of 262 Osmosis withdrawal requests, one exceeded the reserve, and it was paid on 22 July. I could not verify the failure mode itself. The only reachable Nomic RPC reports 0 peers, so it cannot distinguish a halted network from an isolated node. The halt is confirmed instead by the 54-hour checkpoint gap on Bitcoin and by @osmosiszone pausing the pool. Current state 40.63744627 nBTC outstanding against a 0.78126898 BTC reserve, or 1.92% backed. Osmosis paused the allBTC pool at height 70,112,441 on 7 September 19:35:16. is_active is false and redemptions are blocked. get_corrupted_denoms is still empty. Two notes nomic1rk07saqmvfle50h4h9hul00g67xzrcc5ytfxjm has been circulating as the exploiter address. It has 3,100 transactions, all update_client on IBC client 07-tendermint-1. It is a relayer, not the attacker. At 14:09:08 on 7 September, 81 minutes before the halt, an unrelated Osmosis account with an established history swapped 9.00805626 allBTC for WBTC at block 70,097,405 (D43E123EE07576B1445DE95D0747A474E6B756B17920FD4BC7F38D5076BC4092). I have no evidence about motive and am not claiming any.
14
7
58
13,283
Ray Raspberry retweeted
.@injective halted for 3h 42m on 31 August. Here is what the chain records, pulled from archive nodes. The halt: last block 181,027,006 at 16:10:02 UTC, next block 181,027,007 at 19:52:14. Height advanced by one across the seam, so nothing was rolled back — the opposite of what @CronosNetwork did the day before. From roughly 15:31 block times went from 0.62s to 23.3s. The final block carried 213 transactions against a 0–28 norm. The vector is the insurance fund path. One address, inj10ykxh78wvp8da6q8xfck3tufl0ux8sp8rulp7p, sent 7,109 transactions over 19 hours: 299 MsgCreateInsuranceFund 299 MsgInstantBinaryOptionsMarketLaunch 1,188 MsgCreateBinaryOptionsLimitOrder 1,134 MsgWithdraw 920 MsgDeposit The 1:1 on the first two is the whole story. Instant binary options market launch is permissionless by design — post an insurance fund, get a market. It was cycled 299 times. The executor still holds 299 shareNNN denominations in a contiguous run from share430 to share728, one receipt per fund. Working capital was 9,110 USDT bridged through Peggy at 01:02:47. First exploit transaction at 01:12:24. Last at 20:17:16, which is 25 minutes after the chain came back up. The money did not move far. Proceeds sit at 0x5a18c382ed5bb01814296ee03026dbf5b32a69ea: 1,979.808450 ETH, about $4.88M, arriving in three sweeps of 1,650.000000, 211.107589 and 118.700000 ETH. No mixer, no Tornado Cash, no exchange deposit of size. The stash holds zero USDC and zero USDT — the stablecoin proceeds were converted before they got there. The executor is down to 0.049962 ETH. Someone was watching this live. At 16:02:23 a smart wallet dormant for 17.9 days woke up and sent 0.002 ETH to a fresh address. That address delivered the same message to both attacker wallets — the stash at 16:05:35, the executor at 16:11:59, the second arriving 1m 57s after the chain had already stopped: "Hi. We would like to chat and offer you a bounty. Please get in touch. You can DM our official account on Twitter or message us on Telegram (@ckhbtc)." Three minutes from cold wallet to first contact, and the sender had already mapped both attacker addresses. But it names no organisation, only a Telegram handle, and it came from a burner funded by a personal EIP-7702 smart wallet. That is not how a protocol makes a public bounty offer. Do not report it as Injective's until they confirm it — an anonymous approach to a live attacker holding $4.88M is equally consistent with a third party trying to intercept the funds. Neither message has been answered. The attacker did sign again, six hours later. At 22:15:35 and 22:20:59 the stash sent two zero-value transactions to itself carrying text. Neither references the bounty. One boasts about "getting my balance filled higher" — the only inbound after 05:21:59 was the attacker's own executor wallet emptying itself, 118.749985 ETH down to 0.049962. That is consolidation, not gain. The 1,979.81 ETH is the attacker's realised proceeds. What 299 drained insurance funds cost everyone else is a number only Injective can publish.
6
10
69
13,756
Make of it what you will when @cosmos and @cosmoslabs_io blocks a forensic investigator prior to posting about their security advisories regarding the latest round of exploits. I guess they didn't like being asked about partnering with that @0xZeeve self-proclaimed "doctor"
3
1
62
2,619
Both @cosmos and @0xZeeve use "Dr. Ravi Chamria." Which institution conferred it? Every public bio lists an executive MBA from IIM Lucknow. I can find no doctorate, earned or honorary.
Dr. Ravi Chamria, CEO of @0xZeeve, argues that interoperability will decide whether tokenized deposits can move across banks and ledgers without creating systemic risk. The Inter-Blockchain Communication protocol (IBC) is the solution, and its 5+ year production history demonstrates its battle-tested nature.
4
23
1,953
His own LinkedIn lists education as IIM Lucknow (executive MBA) Crunchbase, RocketReach, TheOrg, YourStory, eChai Ventures list IIM Lucknow, all describe an MBA, none mention a doctorate. "Dr." appears on DComm team page & Zeeve self-published or company-controlled sources.
1
7
193
A dissertation in a university repository or ProQuest: not found An honorary doctorate press release naming him: not found (the ones that exist are the other Chamaria) A university convocation record: not found Google Scholar profile with a doctoral affiliation: not found
2
111
Aug 9. @cosmoslabs_io enterprise partner @0xZeeve's flagship @txEcosystem drained. Different codebase than Gravity Bridge. Same attack. Fake deposit. Verification accepted it. Real assets out. Devs copying Gravity Bridge's homework.
ALERT: Nearly 200,000 $XRP drained from the Coreum cross-chain bridge, exploiting a flaw in the bridge's deposit verification to create fake balances and trigger real withdrawals
5
1
20
6,711
Staking is about Trust. And trust starts with resilient validators. Zeeve validators on @CoreumOfficial come with: ✅ Intrusion + Malware protection ✅ 24/7 Uptime & Load balancing ✅ Automated updates & monitoring Delegate stress-free. Let Zeeve handle the rest: zeeve.io/blockchain-protocol…
1
324
Looks like a great partnership between @zeeve aka @DComm_Official and @cosmos. Token trajectory of $ATOM and $DCM has alignment. Maybe chains will have alignment too... Zeeve and DComm tweeting at each other like it's not the same people running both orgs.
We're excited about what our partnership with @0xZeeve brings for digital assets for banks. As Zeeve Co-Founder and CEO Ravi Chamria @rpchamria put it, enterprises want infrastructure that's proven in production, paired with a partner who can get them there safely. And this is what our partnership is about.
2
1
19
1,978
If Wells Fargo built on @cosmos, Cosmos Labs would have a press release. A $2.3 trillion bank on your stack is not a quiet tweet. It's a co-branded announcement. Cosmos Labs published nothing about Wells Fargo. They published a Zeeve partnership. Those are not the same thing.
I am beyond excited to see @WellsFargo announce its @cosmos blockchain, enabling tokenized deposits for corporate clients! Wells Fargo's blockchain is built on Cosmos, leveraging our superior interoperability, programmability, and reliability. wsj.com/finance/banking/well…
16
3
76
15,588