Cosmos co-founder says a major security vulnerability has been uncovered on IBC

Published at: Oct. 13, 2022

On Thursday, Ethan Buchman, co-founder of interblockchain communication (IBC) ecosystem Cosmos, said that a 'critical security vulnerability' had been discovered that 'impacts all IBC-enabled Cosmos chains, for all versions of IBC.' Buchman assured that steps have already been taken to ensure that all major public IBC-enabled chains have been patched, stating: 

"A chain is safe from the critical vulnerability as soon as ⅓ of its voting power has applied the patch. Chains should still seek to patch to ⅔ as quickly as possible once the official patch is released."

A public version of the patch will be released in the CosmosSDK (software development kit) v0.45.9 and v0.46.3 tomorrow at 14:00 UTC. Buchman recommends that all chains and validators apply it immediately upon release, and that chain-halting is not required for it to take effect.

The issue appears to have come to light after core developers of Cosmos and Osmosis (the leading decentralized exchange on Cosmos) ramped up security audits in light of a $100 million cross-chain bridge exploit on BNB Chain on October 6. 

Cross-chain bridges solve a variety of problems in decentralized finance by allowing users to port digital assets across multiple protocols. However, they tend to be more complex than regular decentralized applications, and if the source code is copy-and-pasted across protocols, the vulnerability can be amplified dramatically.

Nevertheless, the vast majority of cross-chain bridge hacks this year, such as the Ronin and Nomad bridge exploits, have occurred on Ethereum Virtual Machine blockchains. On the contrary, security breaches on chains in the Cosmos' IBC ecosystem have been far and few in between. There are currently about 45 blockchains built using the Cosmos SDK. 

Tags
Related Posts
The remaining steps to mainstream institutional investment
It has been said that you only get one chance to make a first impression. Perhaps the best example of this old adage is the cryptocurrency space. From exit scams and money laundering, to unaudited code and high carbon footprints, the crypto landscape has spent the better part of the past decade scrubbing itself of its infamous past. For many, the sanitizing of the decentralized ecosystem was inevitable — simply a matter of when, not if. This mindset hindered the sense of urgency that should have been on display and may have ultimately contributed to the skepticism exhibited by mainstream …
Adoption / May 29, 2021
Supply chain tokens see triple-digit gains as the global economy recovers
Over the last few weeks, blockchain projects focused on supply chains and logistics have seen tremendous growth as the coronavirus-induced economic gridlock begins to loosen and future concerns related to the global pandemic subside. Three logistics projects that have benefited from the improving economic outlook are OriginTrail, Waltonchain and Wabi. Since early February, each has seen its token price increase by up to 300%. TRAC/USD OriginTrail is a self-described “ecosystem dedicated to making global supply chains work together by enabling a universal, collaborative and trusted data exchange.” The project was established in 2011 with the goal of providing enterprise users …
Technology / March 15, 2021
SEC vs. Telegram: Part 2 — The case against integrating the two prongs of a SAFT
As discussed in the previous article, Telegram is a popular global instant messaging company. In 2018, it sold contractual rights to acquire a new crypto asset that it was developing (to be called Grams) to a group of accredited (and wealthy) investors around the world. Telegram raised about $1.7 billion from 171 investors, including 39 U.S. purchasers. This was a prelude to the planned launch of Grams, which was to occur about a year and a half later in October 2019. This two-step process — where a crypto entrepreneur sells contractual rights to acquire a crypto asset upon launch in …
Technology / Sept. 22, 2020
KuCoin Labs Launches $100 Million Venture Capital Fund To Empower Early-Stage Metaverse Projects
KuCoin Labs, the company behind the world's sixth-largest cryptocurrency exchange by trading volume with more than 500 crypto assets listed, announced on Wednesday that it would be launching a $100 million metaverse fund for early-stage projects. The money is also available for entities that develop blockchain-based games, nonfungible tokens, and decentralized applications. In addition, Kucoin will also provide business incubation services, branding, incentives, and business partnerships for developers selected into the fund. Johnny Lyu, CEO of Kucoin, said the following in a prepared statement obtained by Cointelegraph: "KuCoin Metaverse Fund will be launched to accelerate the evolution of the Internet …
Adoption / Nov. 17, 2021
YouTube head of gaming Ryan Wyatt to resign and join Polygon Studios as CEO
On Tuesday, Ryan Wyatt, head of gaming at YouTube, announced he would be leaving the video-sharing platform in February. Partly due to his leadership, YouTube Gaming sees over 250 million daily logged users per day with hundreds of billions of watch time each year. Wyatt cited his passion for blockchain and Web 3.0 development in explaining his resignation. H will soon join Polygon Studios as its CEO. Polygon Studios is the gaming and non-fungible tokens, or NFTs, arm of the namesake layer two Ethereum (ETH) scaling network (MATIC). Polygon plans to commit $100 million to projects led by its subsidiary …
Technology / Jan. 25, 2022