A critical vulnerability in ibc-go, the reference implementation of the Cosmos Inter-Blockchain Communication (IBC) Protocol, has been fixed with no loss

PANews reported on April 24 that Asymmetry Research disclosed in a blog post that there is a vulnerability in ibc-go, the reference implementation of the Cosmos IBC (Cross-Blockchain Communication) protocol, and a re-entrancy vulnerability when processing timeout information may allow attackers to Token an unlimited number of IBCs on-chain minting the affected Cosmos. Although this vulnerability has existed since the inception of ibc-go, recent developments in the Cosmos SDK ecosystem, particularly the CosmWasm-based IBC middleware, have made the vulnerability exploitable. The vulnerability was privately disclosed through the Cosmos HackerOne bug bounty program, and the issue has now been fixed. There was no malicious exploitation and no loss of funds.

ATOM3.21%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)