BPOI Banner
Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

Cosmos co-founder Jae Kwon has raised concerns about the integrity and security of the Cosmos Hub’s liquid staking module (LSM), noting that individuals linked to Democratic People’s Republic of Korea (DPRK) contributed significantly to its development.

In a Tuesday GitHub post, Kwon explained that “for sixteen months […] the LSM was developed by individuals linked to North Korea, and their contributions were integrated into the Cosmos Hub without proper security vetting.” He attributed this oversight to “gross negligence” by the Cosmos validator hosting firm Iqlusion and its leader, Zaki Manian.

Kwon’s concern is presumably that DPRK-linked actors have worked towards completing a so-called “supply chain attack” on Cosmos infrastructure. In such an attack, malicious developers infiltrate projects to embed vulnerabilities in the code that can later be exploited. This is a technique that’s become a trademark of DPRK hackers, as the United Kingdom’s National Cyber Security Centre reported at the end of 2023.

Kwon explained that LSM’s design allows “for stakers to evade slashing by tokenizing their delegations.”

Josh Lee, the co-founder of decentralized exchange Osmosis, explained in an Oct. 16 tweet that “the premise of proof-of-stake is that it is secure because there is accountability of the stakeholders.” He said this would allow an attacker to take control of the chain by holding a big enough stake without being exposed to slashing.

Manian and Iqlusion did not immediately respond to a request for comment from Decrypt.

Iqlusion and Manian began developing the LSM in August 2021 with developers Jun Kai and Sarawut Sanit. Kwon later claimed these individuals were North Korean agents and that they contributed most of the code.

According to Kwon, Manian was aware of the involvement of individuals linked to North Korea since March 2023 as admitted on social media. Despite this, he allegedly did not disclose this information or address other unresolved security issues until earlier this month.

“Rather than taking proactive measures, such as conducting an additional audit or disclosing this issue to the Cosmos community, Zaki publicly asserted that the module was ‘ready to be deployed,'” Kwon wrote. He said Zaki’s lack of transparency represents “poor judgment represents a profound breach of the trust placed in Iqlusion by the Cosmos community.”

An audit in 2022 discovered critical vulnerabilities in the LSM, which Kwon alleged were addressed by the same individuals linked to North Korea. He also claimed that the last code merge involved these contributors. Manian said he rewrote the LSM code, presumably before deployment, along with the staking firm Stride.

Kwon further asserted that since the LSM is not a standalone module, but a collection of modifications and extensions built on top of existing Cosmos staking modules, any vulnerabilities could pose significant risks to all staked ATOM tokens.

He called on the Cosmos governance community to conduct a comprehensive audit of the LSM immediately. Additionally, he urged the Interchain Foundation to implement stricter auditing requirements and develop an oversight protocol to ensure safety in new Cosmos implementations.

The news follows the United States Federal Bureau of Investigations warning last month that DPRK-linked actors were now conducting “difficult-to-detect social engineering campaigns” against those working in the crypto sector.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Adrian Zmudzinski

https://decrypt.co/286539/developers-linked-to-north-korea-helped-develop-cosmos-staking-module-says-co-founder

2024-10-16 15:46:03

bitcoin
Bitcoin (BTC) $ 91,239.45 3.47%
ethereum
Ethereum (ETH) $ 3,150.86 2.37%
tether
Tether (USDT) $ 1.00 0.01%
solana
Solana (SOL) $ 220.97 5.96%
bnb
BNB (BNB) $ 624.84 0.47%
dogecoin
Dogecoin (DOGE) $ 0.378608 2.41%
xrp
XRP (XRP) $ 0.913376 10.09%
usd-coin
USDC (USDC) $ 0.99989 0.01%
staked-ether
Lido Staked Ether (STETH) $ 3,149.25 2.30%
cardano
Cardano (ADA) $ 0.737891 23.23%
tron
TRON (TRX) $ 0.189822 6.38%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 7.48%
avalanche-2
Avalanche (AVAX) $ 34.43 9.10%
the-open-network
Toncoin (TON) $ 5.43 3.19%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,714.53 1.84%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 91,118.41 3.59%
sui
Sui (SUI) $ 3.87 21.67%
pepe
Pepe (PEPE) $ 0.000023 8.15%
weth
WETH (WETH) $ 3,155.65 2.45%
chainlink
Chainlink (LINK) $ 14.26 8.74%
bitcoin-cash
Bitcoin Cash (BCH) $ 434.26 3.40%
polkadot
Polkadot (DOT) $ 5.25 8.37%
near
NEAR Protocol (NEAR) $ 6.10 12.24%
leo-token
LEO Token (LEO) $ 7.76 4.29%
aptos
Aptos (APT) $ 12.48 8.93%
litecoin
Litecoin (LTC) $ 83.75 2.47%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,312.08 2.20%
uniswap
Uniswap (UNI) $ 8.81 8.23%
usds
USDS (USDS) $ 0.994887 0.73%
crypto-com-chain
Cronos (CRO) $ 0.168688 6.63%
stellar
Stellar (XLM) $ 0.145269 7.05%
internet-computer
Internet Computer (ICP) $ 9.04 12.88%
bittensor
Bittensor (TAO) $ 535.96 6.33%
dogwifcoin
dogwifhat (WIF) $ 3.91 11.30%
kaspa
Kaspa (KAS) $ 0.14075 6.24%
ethereum-classic
Ethereum Classic (ETC) $ 23.58 6.26%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.32 8.00%
dai
Dai (DAI) $ 0.999775 0.03%
whitebit
WhiteBIT Coin (WBT) $ 22.30 0.77%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.07%
bonk
Bonk (BONK) $ 0.000044 26.91%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.379814 6.09%
hedera-hashgraph
Hedera (HBAR) $ 0.078807 17.82%
blockstack
Stacks (STX) $ 1.94 6.83%
render-token
Render (RENDER) $ 7.35 11.86%
monero
Monero (XMR) $ 144.09 3.05%
okb
OKB (OKB) $ 44.19 1.81%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.18%
floki
FLOKI (FLOKI) $ 0.000265 24.42%
aave
Aave (AAVE) $ 169.45 8.86%