bitcoin
bitcoin

$95825.255701 USD

-3.05%

ethereum
ethereum

$3332.894258 USD

-4.01%

tether
tether

$0.999354 USD

0.02%

xrp
xrp

$2.159682 USD

-5.84%

bnb
bnb

$690.985892 USD

-1.56%

solana
solana

$188.833370 USD

-4.85%

dogecoin
dogecoin

$0.313957 USD

-5.29%

usd-coin
usd-coin

$1.000187 USD

0.02%

cardano
cardano

$0.862775 USD

-5.54%

tron
tron

$0.251618 USD

-2.29%

avalanche
avalanche

$37.568706 USD

-6.97%

toncoin
toncoin

$5.728405 USD

-4.29%

chainlink
chainlink

$22.820253 USD

-7.02%

shiba-inu
shiba-inu

$0.000022 USD

-5.51%

sui
sui

$4.217685 USD

-6.88%

Cryptocurrency News Articles

Cosmos IBC Protocol Critical Security Flaw Patched, Protecting $126 Million

Apr 24, 2024 at 09:53 am

A critical security bug in the Cosmos Inter-Blockchain Communication (IBC) protocol has been fixed, potentially safeguarding over $126 million. The vulnerability, discovered and privately reported by Asymmetric Research, could have enabled reentrancy attacks, allowing hackers to mint infinite tokens on IBC-connected chains. Rate limiting mechanisms prevented malicious exploitation. The bug, present since 2021, became exploitable after the introduction of IBC middleware. Cosmos developers patched the vulnerability three weeks ago, highlighting the need for ongoing cross-chain security research to protect the multichain ecosystem.

Cosmos IBC Protocol Critical Security Flaw Patched, Protecting $126 Million

Critical Security Flaw in Cosmos IBC Protocol Patched, Protecting $126 Million in Assets

A blockchain security firm, Asymmetric Research, has disclosed a "critical" vulnerability in the Inter-Blockchain Communication (IBC) protocol of the Cosmos network, which placed at least $126 million in crypto assets at risk. The vulnerability, privately reported to Cosmos via its HackerOne Bug Bounty program, has been resolved through a patch.

"No malicious exploitation took place and no funds were lost," Asymmetric Research stated on April 23rd.

The bug, present in ibc-go since its launch in 2021, could have been exploited to execute a reentrancy attack, enabling hackers to mint an infinite number of tokens on IBC-connected chains such as Osmosis and other decentralized finance ecosystems within the Cosmos network.

"We believe at least 126M+ in assets could have been stolen on Osmosis," Asymmetric Research stated. "However, rate limiting on Osmosis slows down the damage that could be caused."

Rate limiting mechanisms are employed to prevent or mitigate attacks designed to overwhelm systems by controlling the rate of request submissions.

The exploit became possible only after Cosmos developers introduced IBC middleware, a third-party application that allows ICS20 tokens (interchain token standard) to be transferred across chains.

Asymmetric Research emphasized the vulnerability highlights the potential risks associated with introducing new features and functionalities, as well as the importance of implementing defense-in-depth strategies to protect blockchain ecosystems.

"This vulnerability highlights the critical need for more research into cross-chain security risks to protect the multichain ecosystem better," the firm stated.

The Cosmos development team, led by Carlos Rodriguez, patched the vulnerability approximately three weeks ago, as evidenced by a GitHub commit.

In October 2022, another "critical" security vulnerability was identified in the IBC protocol, affecting all IBC-connected chains. However, a patch was released before the flaw could be exploited.

The Cosmos network, known for its interoperable blockchain architecture, has experienced several security incidents in the past. In February 2023, a vulnerability in the Gravity Bridge, a cross-chain bridge connecting Cosmos to the Ethereum network, resulted in the theft of approximately $190 million in crypto assets.

The recent IBC protocol vulnerability underscores the ongoing need for vigilance and continuous efforts to enhance the security of cross-chain communication protocols that facilitate the interoperability of different blockchain networks.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Dec 27, 2024