BPOI Banner
Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module

Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module

Cosmos creator All in Bits (AiB) recently issued an urgent alert, revealing that the Liquid Staking Module (LSM) of the Cosmos Hub poses severe security risks since it was developed by individuals linked to North Korea.

AiB believes the developers’ contributions were integrated into the Cosmos Hub without sufficient security vetting, raising alarms over potential vulnerabilities.

Developers With Confirmed Links to North Korea

Initially developed in 2021 under the leadership of Cosmos validator hosting firm Iqlusion and its leader Zaki Manian, with contributions from Stride Labs, Binary Builders, and Informal Systems, the LSM was intended to modify key Cosmos modules like staking, distribution, and slashing. However, its integration into the Cosmos Hub, via Gaia, means that these vulnerabilities could potentially impact all staked ATOMs.

In an update, Cosmos co-founder Jae Kwon said that AiB examined the actions and omissions done by Manian during the development and promotion of the LSM, and raised serious concerns about the transparency and safety of the Cosmos Hub.

The timeline of events surrounding the development and security concerns of the LSM for the Cosmos Hub reveals a series of missteps, as per Kwon.

On June 24, 2021, the Interchain Foundation (ICF) announced that Iqlusion had secured funding for ongoing work on Gaia, network upgrades, and staking derivatives. By August of the same year, Manian and Iqlusion began developing the LSM, with major contributions from Jun Kai and Sarawut Sanit, later identified as linked to North Korea.

A critical audit by Oak Security in July 2022 uncovered significant vulnerabilities, particularly regarding slashing evasion. Shockingly, the same North Korean developers responsible for the original code were tasked with addressing these issues, undermining the integrity of the remediation process.

Despite these findings, Kwon claimed that Manian communicated with the FBI in March 2023 regarding the developers’ ties to North Korea but did not disclose this to the community. Following this, Stride Labs attempted to enhance security in April 2023, yet their work largely involved porting the original code with minimal refactoring.

On April 19, 2023, a Signaling Proposal to integrate the LSM onto the Cosmos Hub was submitted, despite the unresolved security issues. This proposal progressed through various stages, leading to the LSM’s integration on September 11, 2023, which occurred 19 months after the last audit.

Ultimately, Manian publicly acknowledged on October 2, 2024, that he had been aware of the DPRK connections since March 2023 but failed to inform the Cosmos community before advocating for the LSM integration, raising significant concerns about transparency and security within the Cosmos ecosystem.

Cosmos Exec Calls for Accountability

Kwon called for a comprehensive audit of the LSM and full disclosure regarding the involvement of North Korean-linked developers. Additionally, the Cosmos co-founder also advocated for the Interchain Foundation to implement a blacklist of individuals and entities promoting insecure protocols, including Manian and Iqlusion.

He also stressed the need to establish audit requirements for ICF-subsidized code development and develop oversight protocols to ensure rigorous safety assessments of code before new implementations are proposed for the Cosmos Hub.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER 2024 at BYDFi Exchange: Up to $2,888 welcome reward, use this link to register and open a 100 USDT-M position for free!

Source link

Chayanika Deka

https://cryptopotato.com/cosmos-creator-raises-alarm-over-north-korean-links-in-liquid-staking-module/

2024-10-16 13:14:05

bitcoin
Bitcoin (BTC) $ 95,340.54 1.99%
ethereum
Ethereum (ETH) $ 3,320.00 1.01%
tether
Tether (USDT) $ 1.00 0.11%
xrp
XRP (XRP) $ 2.19 2.09%
bnb
BNB (BNB) $ 660.29 0.49%
solana
Solana (SOL) $ 182.24 0.44%
dogecoin
Dogecoin (DOGE) $ 0.316593 0.51%
usd-coin
USDC (USDC) $ 1.00 0.19%
staked-ether
Lido Staked Ether (STETH) $ 3,312.62 0.89%
cardano
Cardano (ADA) $ 0.895638 0.47%
tron
TRON (TRX) $ 0.245598 0.08%
avalanche-2
Avalanche (AVAX) $ 37.10 1.07%
chainlink
Chainlink (LINK) $ 22.75 2.60%
the-open-network
Toncoin (TON) $ 5.45 2.54%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,882.48 2.53%
shiba-inu
Shiba Inu (SHIB) $ 0.000022 0.30%
sui
Sui (SUI) $ 4.34 3.74%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 95,119.49 1.79%
stellar
Stellar (XLM) $ 0.359965 1.94%
polkadot
Polkadot (DOT) $ 6.98 0.05%
hedera-hashgraph
Hedera (HBAR) $ 0.262011 3.72%
hyperliquid
Hyperliquid (HYPE) $ 28.85 16.97%
weth
WETH (WETH) $ 3,316.37 0.92%
bitcoin-cash
Bitcoin Cash (BCH) $ 447.09 1.44%
leo-token
LEO Token (LEO) $ 9.40 0.74%
uniswap
Uniswap (UNI) $ 14.08 3.09%
litecoin
Litecoin (LTC) $ 102.22 1.97%
pepe
Pepe (PEPE) $ 0.000018 3.27%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,502.29 0.87%
near
NEAR Protocol (NEAR) $ 5.11 1.88%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.12%
bitget-token
Bitget Token (BGB) $ 4.12 1.31%
usds
USDS (USDS) $ 0.996334 0.31%
aptos
Aptos (APT) $ 9.26 1.06%
aave
Aave (AAVE) $ 321.92 8.08%
internet-computer
Internet Computer (ICP) $ 10.06 0.13%
crypto-com-chain
Cronos (CRO) $ 0.15482 0.89%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.480228 0.79%
mantle
Mantle (MNT) $ 1.19 2.75%
ethereum-classic
Ethereum Classic (ETC) $ 26.36 1.01%
vechain
VeChain (VET) $ 0.045795 0.83%
render-token
Render (RENDER) $ 7.16 1.23%
whitebit
WhiteBIT Coin (WBT) $ 24.44 0.74%
mantra-dao
MANTRA (OM) $ 3.69 2.12%
monero
Monero (XMR) $ 189.95 0.98%
dai
Dai (DAI) $ 1.00 0.15%
bittensor
Bittensor (TAO) $ 455.85 0.30%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.28 1.24%
arbitrum
Arbitrum (ARB) $ 0.758152 1.28%
ethena
Ethena (ENA) $ 1.07 4.57%