Skip to content

Releases: solva-solutions/neutron

v11.3.0

Choose a tag to compare

@monopauli monopauli released this 29 Sep 10:38
b83729a

Consensus breaking release. neutron-1 has already restarted from halt height 61635573 with this code. Validators running the pre-built recovery binary can keep running it or switch to a build from this tag.

Restart info:

This release publishes the source of the binary that resumed neutron-1 after the governance proposal #9 exploit, together with the fix for the CosmWasm security advisory . All recovery logic is gated on chain id neutron-1 and block height, so blocks up to and including the halt at 61635573 replay exactly as before.

What's Changed

v11.3.0 upgrade

  • Added v11.3.0 upgrade handler
  • Bump wasmd to neutron-wasmd v0.61.15-neutron and wasmvm to v3.0.8 (CosmWasm security fix)

One-time recovery at height 61635575

  • Restore the 11 contracts changed by proposal #9: code id, cw2 contract_info and each contract's own pre-attack admin. No migrate entry point is called
  • Remove the undelegations manager contract tick & burn cron schedule and make x/gov the owner of the auth proxy
  • Unstake the delegation that passed proposal #9 (neutron1ekgfga6vv4zdrrjn3dux6f62fuzektfndgaehm → POSTHUMAN) without an unbonding period
  • Claw back the exploited funds and the unstaked NTRN to the recovery multisig neutron1yr29fd7uzdjp2jsq8hrta8mvyd6ex7vumn0shy

Protections from height 61635574 on

  • Account lock: neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605 and neutron1ekgfga6vv4zdrrjn3dux6f62fuzektfndgaehm can no longer sign, pay or grant fees, or authorize authz messages
  • New-stake freeze: MsgDelegate, MsgCreateValidator and MsgCancelUnbondingDelegation are rejected, in the ante handler and on the message router (covers contracts, ICA and authz). Undelegate, redelegate and unjail keep working
  • Governance filter: only software-upgrade and text proposals can be submitted and executed

🐳 Docker

Image Architecture
solvasolutions/neutron:v11.3.0 amd64

Canonical repositories

Repository Purpose Canonical maintenance location
neutron-org/neutron Neutron node implementation solva-solutions/neutron
neutron-org/connect General purpose oracle implementation via vote extensions solva-solutions/neutron-connect
neutron-org/cosmos-sdk Cosmos SDK fork for Neutron specific hooks solva-solutions/neutron-cosmos-sdk
neutron-org/wasmd Wasmd fork solva-solutions/neutron-wasmd
neutron-org/feemarket EIP-1559 feemarket implementation solva-solutions/neutron-feemarket

Full Changelog: v11.2.1...v11.3.0

v11.2.1

Choose a tag to compare

@monopauli monopauli released this 07 Sep 10:05
3c38927

⚠️ Security Release

This release mitigates a vulnerability.

🚨 Do Not Build From Source

You must use the attached pre-built binary or Docker image provided in this release.

🚨 Additional security hardening required on Linux hosts

Enable & Verify Full ASLR

Direct Host Check: sysctl kernel.randomize_va_space

  • 0: ASLR disabled
  • 1: Partial ASLR enabled
  • 2: Full ASLR enabled (Required)

If the output is not 2, explicitly set full ASLR: sudo sysctl -w kernel.randomize_va_space=2

Persist the setting so it survives a reboot:
echo 'kernel.randomize_va_space = 2' | sudo tee /etc/sysctl.d/60-aslr.conf
sudo sysctl --system

Docker Check: docker run --rm alpine:3.21 cat /proc/sys/kernel/randomize_va_space
Full ASLR is enabled only if it prints 2
Kubernetes Check: kubectl debug node/<node_name_where_neutrond_is_ran> -it --image=alpine:3.21 -- cat /proc/sys/kernel/randomize_va_space
Full ASLR is enabled only if it prints 2

🐳 Docker

Image Architecture
solvasolutions/neutron:v11.2.1 amd64

Canonical repositories

Repository Purpose Canonical maintenance location
neutron-org/neutron Neutron node implementation solva-solutions/neutron
neutron-org/connect General purpose oracle implementation via vote extensions solva-solutions/neutron-connect
neutron-org/cosmos-sdk Cosmos SDK fork for Neutron specific hooks solva-solutions/neutron-cosmos-sdk
neutron-org/wasmd Wasmd fork solva-solutions/neutron-wasmd
neutron-org/feemarket EIP-1559 feemarket implementation solva-solutions/neutron-feemarket

v11.2.0

Choose a tag to compare

@monopauli monopauli released this 24 Aug 11:56
f19c3a7

COORDINATED MAINNET UPGRADE ON HEIGHT 61317700. DO NOT APPLY MANUALLY.

Instructions: download the attached neutrond-linux-amd64 binary and place it in Cosmovisor's upgrade directory before the upgrade height. Cosmovisor upgrade name: v11.2.0.

This release patches a reported security vulnerability and updates Neutron-specific dependencies to Solva-maintained forks, following Solva's appointment as Neutron's security maintainer.

Upgrade details

  • Chain: neutron-1
  • Upgrade name: v11.2.0
  • Height: 61317700
  • Expected time: Thursday, 27 August 2026, approximately 16:00 CEST (14:00 UTC)

🐳 Docker

Image Architecture
solvasolutions/neutron:v11.2.0 amd64

Canonical repositories

Repository Purpose Canonical maintenance location
neutron-org/neutron Neutron node implementation solva-solutions/neutron
neutron-org/connect General purpose oracle implementation via vote extensions solva-solutions/neutron-connect
neutron-org/cosmos-sdk Cosmos SDK fork for Neutron specific hooks solva-solutions/neutron-cosmos-sdk
neutron-org/wasmd Wasmd fork solva-solutions/neutron-wasmd
neutron-org/feemarket EIP-1559 feemarket implementation solva-solutions/neutron-feemarket