Neutron Proposal #9 Passes Amid Multimillion-Dollar Incidents at Astroport and Drop
Security tracker SlowMist recorded estimated losses of $4.9 million at Astroport and $4.4 million at Drop following a governance proposal.
Quick Look
- Neutron voters passed proposal #9 on Sept.
- 22, as security tracker SlowMist recorded estimated losses of $4.9 million at Astroport and $4.4 million at Drop following administrative updates.
AI-generated summary
Why It Matters
Neutron voters passed proposal #9 on Sept. 22, involving 11 'Update Admin' actions on the chain explorer.
Neutron voters passed proposal #9 on Sept. 22, with 11 “Update Admin” actions listed on the chain explorer. The same day, security tracker SlowMist recorded estimated losses of $4.9 million at Astroport and $4.4 million at Drop.
The tracker’s combined estimate of $9.3 million reflects the reported incidents.
Neutron’s governance documentation calls its DAO the network’s highest governing authority and describes its power to execute messages through governance. “Update Admin” is the action identified on the proposal index.
In practical terms, the network’s governance process can change control of a contract’s administrator, even when users experience Astroport or Drop as separate services.
The proposal was titled “AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration.” The explorer marks it as passed and lists 11 administrator updates.
That count describes the proposal’s administrative scope. SlowMist names Astroport and Drop in its Sept. 22 records.
The proposal shows the chain-level route to changing administrators, while the SlowMist entries show the reported financial impact at two applications. Together they point to a risk that is easy to overlook when assessing an application only by its procedures: network governance may retain consequential authority over the software it hosts.
What remains recoverable
The incident estimates leave the final loss unsettled. Protos reported on Sept. 23 that network halts stranded most of the initially affected assets and that the attacker had extracted around one-fifth at the time of its report.
A network halt can contain assets without returning them to users. The reported extraction share measures movement beyond halted networks, but it gives a different view from the incident estimates for application funds.
A final recovery figure requires knowing which assets remain contained, which have been restored, and which have left defenders’ reach. Withdrawal from an application, movement between networks, containment during a halt, and eventual return to a user account are key steps.
For affected users, the unresolved issue is how much of that reported value can actually be returned.
What to Watch
AI outlook — possibilities, not facts
Final recovery figures will be determined based on contained versus extracted assets.
Likely · Within weeks
Open Questions
- How much of the reported value can actually be returned to users?
- Which specific assets remain contained versus extracted?







