When a chain has an emergency, somebody decides, and this week showed who
Decentralised systems are usually described by what nobody can do alone. This week's material is about what happens when something has to be done quickly anyway - and which people end up deciding.
Validators, by coordinated upgrade. After a governance attack on Neutron sent roughly 1.7 million stolen ATOM to the Cosmos Hub, validators with more than a third of voting power halted the Hub. They then restarted on a patched binary that made a single state change: moving 1,227,121 ATOM from the attacker's address to a 4-of-6 multisig. The written plan was circulated before any code shipped, the change touched one account, and the release of funds is tied to a governance process. But the action itself was taken by validators installing software, not by an on-chain vote.
Maintainers, by controlling information. Core Lightning shipped a security release in August under a two-week embargo on its source code, and a later release in September with a few tests withheld, so attackers could not easily reverse-engineer the fixes before operators upgraded. That is a decision about who knows what, and when, taken by the people who maintain the code.
Client developers, by withholding agreement. A Solana proposal to enforce priority ordering within entry batches was closed "pending more discussion" because it lacked acknowledgements from client developers. On a network with several validator clients, the teams that build them effectively hold a veto over consensus rules.

What the three have in common
In each case the formal model - token-holder governance, open source, open proposals - was not where the decision was actually made. It was made by a small, identifiable group with operational control: validators who run nodes, maintainers who hold the release keys, developers who implement the rules. That is not necessarily a failure; emergencies need fast decisions, and small groups make them.
What to look for
The useful question is not whether such groups exist but whether they are constrained. The Cosmos response published its scope before acting and limited the change to one account. Core Lightning lifted its embargo on a stated schedule. The Solana process requires agreement from more than one client. Those constraints, written down in advance, are what separate emergency coordination from discretion.