Odaily News Interchain Labs has confirmed that an individual later identified as being associated with North Korea contributed to the Cosmos codebase between 2022 and 2024 while employed by the former maintainer. The individual had limited access to the cosmos/IAVL and cosmos/cosmos-sdk codebases, and most of his contributed code has been deprecated or excluded from the roadmap, and independent audits have not found risk vulnerabilities. To support transparency, ICL will offer a one-month double bounty on the Cosmos HackerOne page for discovering vulnerabilities related to the participant's GitHub account. After ICL took over the development of the core stack, it implemented new security protocols to prevent further contributions, and the individual was rejected for further positions. ICL has performed security upgrades on all Cosmos core codebases and will deprecate related codebases in the future. This incident highlights the need for strict security procedures in Web3 and the broader technology field. (The Block)