Cryptocurrency

"On the LSM Module"

2024-10-15 [vendor] Cosmos LSM [chain] cosmos
Primary Source ↗
Blockchain(s) Cosmos

Incident Details

Cosmos creator Jae Kwon has raised concerns about a portion of the Cosmos protocol called the “Liquid Staking Module” after learning it was developed by North Korean agents. Although a contributor to the protocol, Zaki Manian, learned of the developers’ links to North Korea after contact from the FBI in March 2023, Kwon claims that Manian ignored known flaws in their code, failed to fully audit their code, and did not report the issue to the project team or the Cosmos community. According to Kwon, the code contained a vulnerability that would allow stakers to avoid having their stakes slashed, which “contradicts the fundamental principles of staking security.“Kwon urged the Cosmos governance team to perform a full audit of the code written by these developers, and develop more protocols to prevent issues like this going forward. He also called for the governance team to blacklist Zaki Manian.

Technical Details

Initial Attack Vector
Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise
Vendor / Product
Cosmos LSM

Timeline

  1. 2024-10-15 Breach occurred
  2. 2024-10-15 Publicly disclosed