Interchain Labs: North Korea-linked attackers accidentally introduced, no security issues found and bounty doubled
06-16 13:15

Odaily News Interchain Labs has confirmed that an individual later identified as being associated with North Korea contributed to the Cosmos codebase between 2022 and 2024 while employed by the former maintainer. The individual had limited access to the cosmos/IAVL and cosmos/cosmos-sdk codebases, and most of his contributed code has been deprecated or excluded from the roadmap, and independent audits have not found risk vulnerabilities. To support transparency, ICL will offer a one-month double bounty on the Cosmos HackerOne page for discovering vulnerabilities related to the participant's GitHub account. After ICL took over the development of the core stack, it implemented new security protocols to prevent further contributions, and the individual was rejected for further positions. ICL has performed security upgrades on all Cosmos core codebases and will deprecate related codebases in the future. This incident highlights the need for strict security procedures in Web3 and the broader technology field. (The Block)

最热快讯
资讯热榜
日榜
周榜
Binance Alpha launches MOMOFUN (MM), with an airdrop threshold of 200 points
A whale bought $300 million worth of ETH from Galaxy in three days, now losing $26 million
Planet Noon News | August 3
Hong Kong RWA registration platform will be launched on August 7
The Satoshi Nakamoto statue in Lugano, Switzerland, which Tether co-created, has been stolen.
Communications Platform Towns Protocol Announces Token Economics: 57% of Tokens Allocated for Airdrops, Grants, and Other Community Initiatives