Cosmos Consensus Layer CometBFT Exposes Critical 0-day Vulnerability, Potentially Causing Validator Node Deadlock

ME News Report, April 21 (UTC+8), security researcher Doyeon Park disclosed a 0-day vulnerability in the Cosmos consensus layer (CometBFT), with a CVSS score of 7.1 (high risk). This vulnerability could cause Cosmos ecosystem nodes supporting over $8 billion in assets to stall during block synchronization, but it does not directly lead to asset theft. Currently, technical details have been disclosed on GitHub, but the researcher has not yet released the full attack code. Doyeon Park stated that due to the Cosmos team’s lack of cooperation during the handling process—including refusing to publicly report the issue, marking their HackerOne report as spam, and violating international standards by downgrading the severity of the vulnerability—he decided to disclose it publicly after multiple unfruitful communications. Park provides a “survival guide” for Cosmos validators, strongly advising against restarting nodes before a patch is released. The vulnerability triggers during block synchronization; if a node is restarted and enters synchronization, exposure to malicious peer nodes may cause a deadlock, preventing it from rejoining the network. (Source: Foresight News)

ATOM1.33%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin