Cosmos Hub halted and moved 1.23 million stolen ATOM to a validator multisig
Cosmos Labs has published an account of how Cosmos Hub validators responded to a governance attack on Neutron, a separate chain in the Cosmos ecosystem. According to the 25 September post, a governance proposal executed on Neutron on 22 September gave the attacker administrative control over contracts of Astroport and other protocols; malicious code was added and funds were drained before Neutron halted. Part of the proceeds, roughly 1.7 million ATOM, was bridged to the Cosmos Hub. The post stresses that the Hub itself was not exploited and no Hub user funds were affected.
Hub validators then acted quickly and unusually. Validators representing more than a third of voting power stopped their nodes at about 11:18 UTC on 22 September, halting the chain at height 33,086,740. By about 15:20 they had a written plan: a one-time change at the halt height moving the attacker's remaining ATOM to a validator-held multisig, with the exact addresses, the six signers and the one-account scope. A patched Gaia binary, v28.3.0, was built, tested against a fork of mainnet and distributed with a checksum by about 19:50. Once validators with more than 67% of voting power confirmed installation, the Hub restarted at 12:00 UTC on 23 September, and at 12:06 1,227,121.37 ATOM moved to a 4-of-6 multisig held by Nansen, Keplr, Enigma, Silknodes, Kiln and Polkachu.
Not everything was caught. The post describes a pending THORChain refund to the attacker's address, identified while the binary was already being distributed; validators chose to proceed rather than lengthen the halt, and those funds were considered lost. The attacker's address has been flagged to more than 30 exchanges, bridges and custodians. Neutron's maintainers are preparing a full post-mortem, and the release of the recovered ATOM is to follow a recovery plan and a Hub governance process.

What it means
The episode shows both sides of validator coordination. It stopped a large amount of stolen money from leaving, within about a day, with a written scope and a limited change. It also shows that a proof-of-stake chain can, when enough validators agree, rewrite a balance outside the normal transaction rules.
The safeguards here were procedural: a public plan before code shipped, a one-account scope, named signers and a governance vote before any refund. How closely those are followed will shape how the precedent is judged.