Scan to download
BTC $74,704.12 -0.48%
ETH $2,321.27 -1.55%
BNB $628.27 +0.56%
XRP $1.43 +1.48%
SOL $87.59 +2.57%
TRX $0.3256 -0.05%
DOGE $0.0969 +0.27%
ADA $0.2527 +1.15%
BCH $447.79 +1.01%
LINK $9.36 +0.51%
HYPE $43.59 -4.56%
AAVE $112.00 +5.34%
SUI $0.9775 +0.59%
XLM $0.1648 +2.85%
ZEC $332.35 -2.86%
BTC $74,704.12 -0.48%
ETH $2,321.27 -1.55%
BNB $628.27 +0.56%
XRP $1.43 +1.48%
SOL $87.59 +2.57%
TRX $0.3256 -0.05%
DOGE $0.0969 +0.27%
ADA $0.2527 +1.15%
BCH $447.79 +1.01%
LINK $9.36 +0.51%
HYPE $43.59 -4.56%
AAVE $112.00 +5.34%
SUI $0.9775 +0.59%
XLM $0.1648 +2.85%
ZEC $332.35 -2.86%

Interchain Labs: North Korean-linked attackers were inadvertently introduced, no security issues found and the bounty doubled

2025-06-16 21:28:46
Collection

ChainCatcher news, according to The Block, Interchain Labs has confirmed that between 2022 and 2024, an individual later identified as being linked to North Korea contributed to the Cosmos codebase while employed by a former maintainer.

The individual had limited access to the cosmos/IAVL and cosmos/cosmos-sdk codebases, and most of their contributed code has been deprecated or excluded from the roadmap, with independent audits finding no security vulnerabilities. To support transparency, ICL will offer a month of double bounties on the Cosmos HackerOne page for discovering vulnerabilities related to this participant's GitHub account.

After ICL took over core stack development, new security protocols were implemented to prevent further contributions, and the individual was denied reapplication for a position. ICL has conducted security upgrades on all Cosmos core codebases and will deprecate the related codebases in the future. This incident highlights the need for stringent security protocols in the Web3 and broader technology sectors.

app_icon
ChainCatcher Building the Web3 world with innovations.