Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Cosmos Developers Patch Critical Security Bug In IBC Protocol

Cosmos Developers Patch Critical Security Bug In IBC Protocol

CryptodailyCryptodaily2024/04/24 09:10
By:Amara Khatri

Table of Contents

  • Critical Security Bug
  • Over $126 Million Were At Risk

Cosmos developers have patched a critical security bug in the Cosmos Inter Blockchain Communication (IBC) protocol that had put at least $126 million at risk. 

Asymmetric Research had privately disclosed details of the vulnerability impacting the Cosmos ecosystem, adding that it was patched before anyone could exploit it. 

Critical Security Bug 

According to Asymmetric Research, the Inter Blockchain Protocol always had the bug. However, it only recently became exploitable thanks to developments in the protocol’s codebase. Once Cosmos was notified of the issue, the vulnerability was quickly patched before anyone could exploit it. Asymmetric Research stated in a blog post, 

“A reentrancy vulnerability during the handling of timeout messages could have allowed an attacker to mint an infinite amount of IBC tokens on affected Cosmos chains. While this vulnerability has existed in IBC-go since the beginning, it only became exploitable due to recent developments in the Cosmos SDK ecosystem, specifically CosmWasm-based IBC middleware. We privately disclosed the vulnerability through the Cosmos HackerOne Bug Bounty program, and the issue is now patched. No malicious exploitation took place, and no funds were lost.”

Jessy Irwin, the CEO of Amulet, a firm engaged by the Interchain Foundation to run its bug bounty program and coordinate security on the Cosmos ecosystem, confirmed that the issue was reported. 

“During the coordination of this issue, both Amulet and the IBC-go team engaged in independent rounds of risk-based impact assessment to identify potentially impacted parties to mitigate its impact.”

Over $126 Million Were At Risk 

According to Asymmetric Research, the bug could have allowed a reentrancy bug, which could have allowed hackers to mint infinite tokens on Inter-Blockchain Communication-Connected chains such as Osmosis and other decentralized finance ecosystems on Cosmos. 

“We believe at least 126M+ in assets could have been stolen on Osmosis. However, rate limiting on Osmosis slows down the damage that could be caused.”

Rate limits can prevent or at least mitigate attacks attempting to overwhelm a system by controlling the rate at which requests are made. Developers on Cosmos launched a third-party application called the IBC-middleware, allowing the ICS20 (Interchain token standard) tokens to cross chains, making the bug exploitable. Asymmetric added in their blog post, 

“This issue demonstrates how easy it is to break trust assumptions and introduce new vulnerabilities by adding new features and functionality. It is also another example of the importance of defense-in-depth. This vulnerability highlights the critical need for more Research into cross-chain security risks to protect the multichain ecosystem better.”

According to Asymmetric CEO Jonathan Claudius, the vulnerability highlights the need for more Research into cross-chain security risks to help protect the multichain ecosystem. 

“This vulnerability highlights the critical need for more Research into cross-chain security risks to protect the multichain ecosystem better. This case demonstrates our capability and ongoing efforts to discover and neutralize existential threats that could undermine the digital economy.”

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Investment Disclaimer
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!