pwshub.com

Cosmos Developer Releases ‘Urgent Warning’ About ATOM Liquid Staking Model, Says North Koreans Wrote Code

The developer of interconnected blockchain network Cosmos (ATOM) is warning that the Liquid Staking Module (LSM) of the Cosmos Hub poses serious security risks.

In a statement, Cosmos co-founder Jae Kwon says that when developer Zaki Manian began building the LSM in August 2021, Jun Kai and Sarawut Sanit, coders who were later linked to North Korea, wrote most of the module’s code.

Kwon says the same North Korean developers also fixed the vulnerabilities identified by an Oak Security audit in July 2022.

“This not only undermined the integrity of the remediation process but also gave the potential creators of the vulnerabilities the opportunity to either fix or obscure any intentional weakness they may have introduced, potentially exposing the system to further risks.”

Kwon says that in March 2023, the FBI informed Manian about the involvement of North Korea in the project, but instead of disclosing the information to the Cosmos community, Manian announced in April 2023 that the LSM was ready to be deployed and pushed the signaling proposal to integrate the LSM into the Cosmos Hub.

By September, the LSM was integrated into the Cosmos Hub with 19 months of unaudited code changes.

Kwon says the Cosmos governance community should take immediate action, warning that the security issues with the LSM could lead to serious consequences.

“It is important to note that the LSM is not a standalone module but rather a series of modifications and extensions built on top of the existing Cosmos staking modules… Consequently, any vulnerability in Iqlusion’s LSM that impacts these core modules could potentially put all staked ATOM at risk, as liquid staking interacts directly with staked assets.”

Generated Image: Midjourney

Source: dailyhodl.com

Related stories
3 weeks ago - The integration of Axelar's MDS by major blockchains could significantly enhance web3's interoperability, fostering a more connected ecosystem. The post Sui, XRP Ledger, EigenLayer set to integrate Axelar’s new Mobius Development Stack...
1 month ago - Token2049 Singapore is arguably the industry’s largest business-driven event, and its ostentatious presentation left no room for moderation.
1 week ago - The Cosmos co-founder attributed the oversight to "gross negligence" by validator hosting firm Iqlusion and its leader, Zaki Manian.
1 month ago - THORChain, a cross-chain decentralized exchange using Cosmos technology, successfully conducted a hard fork yesterday, September 4. However, while the update was highly anticipated, sellers still needed to press on, looking at the...
1 month ago - Layer-1 smart contract platform SUI Network (SUI) is surging after announcing plans to support the stablecoin USDC. In a new blog post, USDC issuer and payments platform Circle says that the network will be adding USDC as well as support...
Other stories
23 minutes ago - A deep-pocketed crypto holder who bought Bitcoin (BTC) more than 14 years ago has suddenly moved the flagship digital asset at a massive profit. On-chain data shows that on Friday, the previously dormant crypto wallet abruptly moved a...
38 minutes ago - Toncoin (TON) has undoubtedly been one of the best performers in the cryptocurrency market in 2024, enjoying a meteoric rise in the first half of the year. However, the altcoin has struggled to keep up the pace just as the other large-cap...
1 hour ago - Federal prosecutors reportedly plan to propose a plea deal to the man who allegedly hacked the U.S. Securities and Exchange Commission’s (SEC) social media platform X account earlier this year. The Department of Justice (DOJ) says Alabama...
1 hour ago - Demand for Bitcoin and Ethereum exchange-traded funds (ETFs) is making other recent ETF launches look small by comparison.
1 hour ago - Bitcoin's potential for a significant price shift could impact market dynamics, influencing investor sentiment and broader financial trends. The post Bitcoin set for ‘huge move’ as Bollinger Bands hit tightest levels appeared first on...