BPOI Banner
Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module

Cosmos Creator Raises Alarm Over North Korean Links in Liquid Staking Module

Cosmos creator All in Bits (AiB) recently issued an urgent alert, revealing that the Liquid Staking Module (LSM) of the Cosmos Hub poses severe security risks since it was developed by individuals linked to North Korea.

AiB believes the developers’ contributions were integrated into the Cosmos Hub without sufficient security vetting, raising alarms over potential vulnerabilities.

Developers With Confirmed Links to North Korea

Initially developed in 2021 under the leadership of Cosmos validator hosting firm Iqlusion and its leader Zaki Manian, with contributions from Stride Labs, Binary Builders, and Informal Systems, the LSM was intended to modify key Cosmos modules like staking, distribution, and slashing. However, its integration into the Cosmos Hub, via Gaia, means that these vulnerabilities could potentially impact all staked ATOMs.

In an update, Cosmos co-founder Jae Kwon said that AiB examined the actions and omissions done by Manian during the development and promotion of the LSM, and raised serious concerns about the transparency and safety of the Cosmos Hub.

The timeline of events surrounding the development and security concerns of the LSM for the Cosmos Hub reveals a series of missteps, as per Kwon.

On June 24, 2021, the Interchain Foundation (ICF) announced that Iqlusion had secured funding for ongoing work on Gaia, network upgrades, and staking derivatives. By August of the same year, Manian and Iqlusion began developing the LSM, with major contributions from Jun Kai and Sarawut Sanit, later identified as linked to North Korea.

A critical audit by Oak Security in July 2022 uncovered significant vulnerabilities, particularly regarding slashing evasion. Shockingly, the same North Korean developers responsible for the original code were tasked with addressing these issues, undermining the integrity of the remediation process.

Despite these findings, Kwon claimed that Manian communicated with the FBI in March 2023 regarding the developers’ ties to North Korea but did not disclose this to the community. Following this, Stride Labs attempted to enhance security in April 2023, yet their work largely involved porting the original code with minimal refactoring.

On April 19, 2023, a Signaling Proposal to integrate the LSM onto the Cosmos Hub was submitted, despite the unresolved security issues. This proposal progressed through various stages, leading to the LSM’s integration on September 11, 2023, which occurred 19 months after the last audit.

Ultimately, Manian publicly acknowledged on October 2, 2024, that he had been aware of the DPRK connections since March 2023 but failed to inform the Cosmos community before advocating for the LSM integration, raising significant concerns about transparency and security within the Cosmos ecosystem.

Cosmos Exec Calls for Accountability

Kwon called for a comprehensive audit of the LSM and full disclosure regarding the involvement of North Korean-linked developers. Additionally, the Cosmos co-founder also advocated for the Interchain Foundation to implement a blacklist of individuals and entities promoting insecure protocols, including Manian and Iqlusion.

He also stressed the need to establish audit requirements for ICF-subsidized code development and develop oversight protocols to ensure rigorous safety assessments of code before new implementations are proposed for the Cosmos Hub.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER 2024 at BYDFi Exchange: Up to $2,888 welcome reward, use this link to register and open a 100 USDT-M position for free!

Source link

Chayanika Deka

https://cryptopotato.com/cosmos-creator-raises-alarm-over-north-korean-links-in-liquid-staking-module/

2024-10-16 13:14:05

bitcoin
Bitcoin (BTC) $ 91,005.38 3.03%
ethereum
Ethereum (ETH) $ 3,079.77 0.35%
tether
Tether (USDT) $ 1.00 0.02%
solana
Solana (SOL) $ 216.77 1.98%
bnb
BNB (BNB) $ 619.35 1.25%
dogecoin
Dogecoin (DOGE) $ 0.375408 0.12%
xrp
XRP (XRP) $ 0.885168 12.69%
usd-coin
USDC (USDC) $ 1.00 0.12%
staked-ether
Lido Staked Ether (STETH) $ 3,077.52 0.24%
cardano
Cardano (ADA) $ 0.738274 25.27%
tron
TRON (TRX) $ 0.192866 8.67%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 4.71%
the-open-network
Toncoin (TON) $ 5.37 1.37%
avalanche-2
Avalanche (AVAX) $ 33.00 4.48%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 90,884.35 3.39%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,657.14 0.22%
sui
Sui (SUI) $ 3.60 6.40%
pepe
Pepe (PEPE) $ 0.000023 5.71%
weth
WETH (WETH) $ 3,075.98 0.40%
chainlink
Chainlink (LINK) $ 13.79 5.05%
bitcoin-cash
Bitcoin Cash (BCH) $ 430.17 2.38%
polkadot
Polkadot (DOT) $ 5.15 6.60%
leo-token
LEO Token (LEO) $ 7.63 3.23%
near
NEAR Protocol (NEAR) $ 5.49 0.51%
aptos
Aptos (APT) $ 11.80 4.31%
litecoin
Litecoin (LTC) $ 83.30 1.45%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,239.37 0.37%
usds
USDS (USDS) $ 0.993193 0.48%
uniswap
Uniswap (UNI) $ 8.55 3.36%
crypto-com-chain
Cronos (CRO) $ 0.169029 12.83%
stellar
Stellar (XLM) $ 0.144926 9.94%
internet-computer
Internet Computer (ICP) $ 8.68 7.49%
dogwifcoin
dogwifhat (WIF) $ 3.84 4.75%
bittensor
Bittensor (TAO) $ 516.20 2.32%
kaspa
Kaspa (KAS) $ 0.137764 2.49%
ethereum-classic
Ethereum Classic (ETC) $ 23.17 5.37%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.28 2.64%
dai
Dai (DAI) $ 0.99957 0.16%
whitebit
WhiteBIT Coin (WBT) $ 22.32 0.68%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.03%
bonk
Bonk (BONK) $ 0.000044 18.86%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.371449 2.70%
blockstack
Stacks (STX) $ 1.87 2.10%
hedera-hashgraph
Hedera (HBAR) $ 0.073352 14.91%
render-token
Render (RENDER) $ 6.88 2.59%
okb
OKB (OKB) $ 43.91 0.55%
monero
Monero (XMR) $ 143.49 3.74%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.25%
filecoin
Filecoin (FIL) $ 4.19 7.28%
aave
Aave (AAVE) $ 164.19 2.91%