Cosmos Network Discloses Critical Vulnerability in Tendermint Core

Published at: Oct. 4, 2019

In a forum post published on Oct. 1 blockchain interoperability platform Cosmos has disclosed a “high-severity security vulnerability” that was found in consensus engine Tendermint Core.

According to the announcement, an update patch was released the following morning. The vulnerability reportedly affected all versions of Tendermint, on which Cosmos is built. All validators and service providers on Tendermint-powered networks are encouraged to update their software as soon as possible.

Blockchain to blockchain communication

The Cosmos platform allows individual blockchains to communicate and transact with each other. Developed by the Tendermint team, it employs an inter-blockchain communication protocol to establish blockchain interoperability.

As Cointelegraph reported in August, it is also one of the top staking projects in the crypto space today.

Recent blockchain vulnerabilities

The Cosmos announcement caps a less than impressive week for blockchain security, with vulnerabilities also revealed in both ZCash and the Lightning Network.

Whilst no further details of the Cosmos bug have been given, the vulnerability in Lightning Network was fully disclosed by a developer this week.

LN nodes accepting funding transactions to open channels needed to check that the transaction was ‘as promised’, or an attacker could spend funds from the channel without paying.

The ZCash bug, announced Sept. 29, could have leaked metadata relating to the IP addresses of shielded full-nodes.

Tags
Related Posts
Sommelier partners with Mysten Labs to launch Cosmos smart contracts
Sommelier, a co-processing protocol to the Ethereum Virtual Machine, or EVM, announced a research and development partnership with Mysten Labs to increase liquidity transaction speeds and launch smart contract applications on the Cosmos blockchain on Tuesday. Founded in 2020 by Zaki Manian, a core developer on the Cosmos protocol, Sommelier is a test-net protocol designed to deliver enterprise-grade automated financial transactions such as limit orders, batched orders and portfolio rebalancing to decentralized finance, or DeFi, traders and liquidity providers, or LPs. The blockchain, which combines the Tendermint consensus layer, Cosmos Stargate SDK, and dual-way Ethereum bridge, will work with Mysten …
Blockchain / Sept. 21, 2021
Building multichain is a new necessity for DeFi products
At present, your DeFi product needs to be multichain to be competitive — this is the hard (and exciting) truth of 2021. Whether you’re building a wallet, a lending service or a DeFi game, your target audience knows that there is more to the crypto space than Ethereum. And they expect you to provide the best of all worlds. It seems there will always be a debate about which blockchain makes for the best foundation for projects. Enhanced security, low transaction costs and formidable speed — there will always be a chain that offers bigger advantages. As the speculators argue …
Technology / Nov. 20, 2021
Solana integrates Web3Auth to lower DApp barrier-to-entry
Solana Labs and Web3Auth have announced a collaborative digital wallet initiative designed to eliminate the prerequisites for seed phrases in cryptocurrency interaction, and in turn, streamline a presently tedious and complex process to drive consumer adoption in the Web3 sphere. The Solana Torus Wallet is a non-custodial product that enables users to access all decentralized applications (DApps) and associated wallets within the Solana ecosystem. Upon creation of a cryptocurrency wallet, a user has required the record and remember a seed phrase; a random computer-generated list of words, typically twelve to twenty-four, which acts as the wallet holders master key to …
Adoption / Feb. 3, 2022
8 hacker tactics to be aware of when protecting your crypto assets
Crypto security is one of the hottest topics for investors and companies actively working on creating better security solutions for the Web3 industry. Web3 Antivirus was created in an effort to make wallet security more accessible to all users in the space. The company offers a browser extension that helps users monitor wallet interactions and spot potential scams and malicious activity before investors fall victim to them. Below are the most common crypto scams and malicious tactics, and how to protect against them below as found through the experience of developing Web3 Antivirus. Malicious transactions Hacker tactics: While on a …
Blockchain / Feb. 6, 2023
Fujitsu launches Web3 acceleration platform for startups and partner companies
The Japanese-based multinational tech company Fujitsu announced the launch of a new platform on Feb 8, designed to support Web3 developers worldwide. According to a report by the Fintech Times, Fujitsu’s Web3 Acceleration Platform seeks to provide a development environment, blockchain-based service APIs, high-computing technologies, simulations, AI, combinatorial optimization, for start-ups, partner companies, and universities building Web3 applications and services. The company said its platform aims to support the creation of a diverse ecosystem of Web3 applications across a range of use cases, such as digital content rights management, business transactions, contracts, and processes. It will also offer free access …
Technology / Feb. 8, 2023