BPOI Banner
Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

Cosmos co-founder Jae Kwon has raised concerns about the integrity and security of the Cosmos Hub’s liquid staking module (LSM), noting that individuals linked to Democratic People’s Republic of Korea (DPRK) contributed significantly to its development.

In a Tuesday GitHub post, Kwon explained that “for sixteen months […] the LSM was developed by individuals linked to North Korea, and their contributions were integrated into the Cosmos Hub without proper security vetting.” He attributed this oversight to “gross negligence” by the Cosmos validator hosting firm Iqlusion and its leader, Zaki Manian.

Kwon’s concern is presumably that DPRK-linked actors have worked towards completing a so-called “supply chain attack” on Cosmos infrastructure. In such an attack, malicious developers infiltrate projects to embed vulnerabilities in the code that can later be exploited. This is a technique that’s become a trademark of DPRK hackers, as the United Kingdom’s National Cyber Security Centre reported at the end of 2023.

Kwon explained that LSM’s design allows “for stakers to evade slashing by tokenizing their delegations.”

Josh Lee, the co-founder of decentralized exchange Osmosis, explained in an Oct. 16 tweet that “the premise of proof-of-stake is that it is secure because there is accountability of the stakeholders.” He said this would allow an attacker to take control of the chain by holding a big enough stake without being exposed to slashing.

Manian and Iqlusion did not immediately respond to a request for comment from Decrypt.

Iqlusion and Manian began developing the LSM in August 2021 with developers Jun Kai and Sarawut Sanit. Kwon later claimed these individuals were North Korean agents and that they contributed most of the code.

According to Kwon, Manian was aware of the involvement of individuals linked to North Korea since March 2023 as admitted on social media. Despite this, he allegedly did not disclose this information or address other unresolved security issues until earlier this month.

“Rather than taking proactive measures, such as conducting an additional audit or disclosing this issue to the Cosmos community, Zaki publicly asserted that the module was ‘ready to be deployed,'” Kwon wrote. He said Zaki’s lack of transparency represents “poor judgment represents a profound breach of the trust placed in Iqlusion by the Cosmos community.”

An audit in 2022 discovered critical vulnerabilities in the LSM, which Kwon alleged were addressed by the same individuals linked to North Korea. He also claimed that the last code merge involved these contributors. Manian said he rewrote the LSM code, presumably before deployment, along with the staking firm Stride.

Kwon further asserted that since the LSM is not a standalone module, but a collection of modifications and extensions built on top of existing Cosmos staking modules, any vulnerabilities could pose significant risks to all staked ATOM tokens.

He called on the Cosmos governance community to conduct a comprehensive audit of the LSM immediately. Additionally, he urged the Interchain Foundation to implement stricter auditing requirements and develop an oversight protocol to ensure safety in new Cosmos implementations.

The news follows the United States Federal Bureau of Investigations warning last month that DPRK-linked actors were now conducting “difficult-to-detect social engineering campaigns” against those working in the crypto sector.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Adrian Zmudzinski

https://decrypt.co/286539/developers-linked-to-north-korea-helped-develop-cosmos-staking-module-says-co-founder

2024-10-16 15:46:03

bitcoin
Bitcoin (BTC) $ 67,750.15 1.41%
ethereum
Ethereum (ETH) $ 2,620.26 0.91%
tether
Tether (USDT) $ 0.999698 0.08%
bnb
BNB (BNB) $ 602.68 1.67%
solana
Solana (SOL) $ 154.80 0.94%
usd-coin
USDC (USDC) $ 0.999687 0.09%
xrp
XRP (XRP) $ 0.549368 1.57%
staked-ether
Lido Staked Ether (STETH) $ 2,619.65 0.91%
dogecoin
Dogecoin (DOGE) $ 0.126618 9.96%
tron
TRON (TRX) $ 0.159959 0.73%
the-open-network
Toncoin (TON) $ 5.25 0.94%
cardano
Cardano (ADA) $ 0.355495 0.11%
avalanche-2
Avalanche (AVAX) $ 28.12 0.35%
shiba-inu
Shiba Inu (SHIB) $ 0.000019 3.66%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,094.62 0.80%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 67,601.11 1.27%
weth
WETH (WETH) $ 2,619.60 0.92%
bitcoin-cash
Bitcoin Cash (BCH) $ 365.23 3.61%
chainlink
Chainlink (LINK) $ 11.32 0.21%
polkadot
Polkadot (DOT) $ 4.34 1.00%
near
NEAR Protocol (NEAR) $ 5.00 0.42%
dai
Dai (DAI) $ 0.999591 0.06%
sui
Sui (SUI) $ 2.11 4.17%
uniswap
Uniswap (UNI) $ 7.62 2.63%
leo-token
LEO Token (LEO) $ 6.06 0.61%
litecoin
Litecoin (LTC) $ 70.11 0.16%
aptos
Aptos (APT) $ 10.12 3.36%
pepe
Pepe (PEPE) $ 0.000011 3.12%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,751.00 0.86%
bittensor
Bittensor (TAO) $ 586.08 0.89%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.44 0.85%
internet-computer
Internet Computer (ICP) $ 7.96 0.87%
kaspa
Kaspa (KAS) $ 0.131401 1.99%
ethereum-classic
Ethereum Classic (ETC) $ 19.47 0.90%
first-digital-usd
First Digital USD (FDUSD) $ 0.999845 0.11%
monero
Monero (XMR) $ 156.33 1.73%
stellar
Stellar (XLM) $ 0.095174 2.53%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.372019 0.90%
blockstack
Stacks (STX) $ 1.85 3.06%
dogwifcoin
dogwifhat (WIF) $ 2.65 2.80%
immutable-x
Immutable (IMX) $ 1.53 1.17%
okb
OKB (OKB) $ 41.15 0.43%
ethena-usde
Ethena USDe (USDE) $ 0.998925 0.01%
whitebit
WhiteBIT Coin (WBT) $ 16.37 0.19%
aave
Aave (AAVE) $ 157.33 0.36%
filecoin
Filecoin (FIL) $ 3.78 0.36%
optimism
Optimism (OP) $ 1.78 3.68%
render-token
Render (RENDER) $ 5.43 0.24%
crypto-com-chain
Cronos (CRO) $ 0.079023 2.02%
mantle
Mantle (MNT) $ 0.624936 1.00%