Security researcher Doyeon Park disclosed a 0-day vulnerability in the Cosmos consensus layer (CometBFT), with a CVSS score of 7.1 (high risk). This vulnerability could cause Cosmos ecosystem nodes supporting over $8 billion in assets to stall during block synchronization, but it does not directly lead to asset theft. The relevant technical details have been published on GitHub, but the researcher has not yet released the full attack code. Doyeon Park stated that due to the Cosmos team’s lack of cooperation during the handling process—including refusing to publicly report, marking their HackerOne report as spam, and violating international standards by downgrading the vulnerability severity—he decided to disclose it publicly after multiple unsuccessful communications.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin