Internet Security

Cosmos co-founder warns of North Korean influence in Cosmos Hub’s LSM

Cosmos co-founder Jae Kwon alleges North Korean agents helped develop Cosmos Hub’s LSM code Kwon accuses Iqlusion’s Zaki Manian of hiding unresolved security risks Kwon urges an immediate audit and stricter oversight for future implementations Cosmos co-founder Jae Kwon has raised serious concerns regarding the integrity of the Cosmos Hub’s liquid staking module (LSM), alleging


Cosmos co-founder warns of North Korean influence in Cosmos Hub's LSM
  • Cosmos co-founder Jae Kwon alleges North Korean agents helped develop Cosmos Hub’s LSM code
  • Kwon accuses Iqlusion’s Zaki Manian of hiding unresolved security risks
  • Kwon urges an immediate audit and stricter oversight for future implementations

Cosmos co-founder Jae Kwon has raised serious concerns regarding the integrity of the Cosmos Hub’s liquid staking module (LSM), alleging that significant portions of its development involved individuals linked to North Korea.

In a statement released on Tuesday, Kwon accused Cosmos validator hosting firm Iqlusion and its leader, Zaki Manian, of “gross negligence” in allowing the module’s integration without adequate security vetting.

Cosmos Hub’s LSM developers North Korea agents

According to Kwon, development of the LSM began in August 2021 under the direction of Iqlusion and Manian, with contributions from developers Jun Kai and Sarawut Sanit.

Kwon alleges that these developers were later identified as North Korean agents and had provided a substantial portion of the module’s code.

Despite awareness of their connections since March 2023, Kwon claimed Manian withheld this information and failed to disclose several unresolved security risks associated with the LSM.

The controversy gained traction following Manian’s social media acknowledgement that he had known about the North Korean-linked developers for months. However, instead of taking preventive actions, such as conducting an additional audit or informing the Cosmos community, Kwon stated that Manian continued to assert the module was “ready to be deployed.”

Kwon accused Manian of a “profound breach of trust” for prioritizing deployment over community safety.

Critical vulnerabilities in the LSM

Security issues had already surfaced during a 2022 audit that revealed critical vulnerabilities in the LSM. These vulnerabilities were reportedly addressed by the same North Korean-linked developers.

Kwon suggested that despite Manian’s claim of rewriting the LSM code before deployment, significant risks persisted, especially since the module was not a standalone feature, but a set of modifications built atop existing Cosmos staking modules.

This could potentially expose all staked ATOM tokens to security threats.

Kwon has called on the Cosmos governance community to initiate a comprehensive audit of the LSM immediately. Additionally, he urged the Interchain Foundation to impose stricter auditing standards and create an oversight framework to ensure the security of future Cosmos implementations.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Internet Security

Stay Safe Online This Holiday With Up to 50% Off Webroot’s Cybersecurity Plans

It may be the season of giving, but there are things you don’t always want to receive. A computer virus is one of them. Unfortunately, cybercriminals don’t take breaks for the holidays, which means you need to do everything in your power to protect yourself against these perpetual naughty listers. Cybersecurity software is the easiest

It may be the season of giving, but there are things you don’t always want to receive. A computer virus is one of them. Unfortunately, cybercriminals don’t take breaks for the holidays, which means you need to do everything in your power to protect yourself against these perpetual naughty listers. Cybersecurity software is the easiest way to ensure you and your family stay safe online, and Webroot is a solid all-in-one software option. See more info below and how to save big before New Year’s Day on this cybersecurity option.

Get Half Off Webroot’s Total Protection Cybersecurity Plan

Right now, new customers can grab a Webroot subscription for up to 50% off. Whether you’re looking to keep the brand-new laptop you plan to get free from malware with a basic antivirus plan, or you want to protect all your family’s devices from viruses, data breaches, and more with Webroot’s Total Protection plan, it’s the best time to save. These deals only lasts until the ball drops, ringing in the New Year, so grab a discounted plan while you still can.

Although IGN hasn’t reviewed this cybersecurity software, our friends at PCMag gave it a “Good” review score earlier this year for Webroot’s Total Protection plan.

What’s Covered in the Webroot Total Protection Plan?

A data breach, phishing email, or malicious download could wreak havoc on your devices or, worse, your identity. Webroot is there to keep you safe from it all, bringing peace of mind even when you slip up and end up somewhere not-too-great online. Webroot’s Total Protection plan provides the most comprehensive coverage, and plans for new customers start at just $89.99 for the first year, thanks to that hefty 50% discount. Below is everything covered if you opt for Total Protection:

1. Antivirus Protection

  • Faster scans than competitors with less software bloat
  • Web Threat Shield and text scam detection to prevent you from visiting malicious

Read More

Continue Reading
Internet Security

Hyundai Group hit by Bitcoin bomb email as police probe copycat extortion

The rise in bomb threats against major corporations highlights growing cybersecurity challenges and the need for enhanced digital defenses. The post Hyundai Group hit by Bitcoin bomb email as police probe copycat extortion appeared first on Crypto Briefing…

The rise in bomb threats against major corporations highlights growing cybersecurity challenges and the need for enhanced digital defenses.
The post Hyundai Group hit by Bitcoin bomb email as police probe copycat extortion appeared first on Crypto Briefing…
Read More

Continue Reading
Internet Security

Over 25,000 FortiCloud SSO devices exposed to remote attacks

Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. …

Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. …
Read More

Continue Reading
Internet Security

Taoiseach warns that US airport security demand for access to five years of social media activity is ‘unworkable’

Taoiseach Micheál Martin hailed US president Donald Trump as “a sensible guy” as he warned a US demand for access to five years of social media activity as part of American visa screening was simply unworkable…

Taoiseach Micheál Martin hailed US president Donald Trump as “a sensible guy” as he warned a US demand for access to five years of social media activity as part of American visa screening was simply unworkable…
Read More

Continue Reading