Internet Security

Cosmos co-founder warns of North Korean influence in Cosmos Hub’s LSM

Cosmos co-founder Jae Kwon alleges North Korean agents helped develop Cosmos Hub’s LSM code Kwon accuses Iqlusion’s Zaki Manian of hiding unresolved security risks Kwon urges an immediate audit and stricter oversight for future implementations Cosmos co-founder Jae Kwon has raised serious concerns regarding the integrity of the Cosmos Hub’s liquid staking module (LSM), alleging


Cosmos co-founder warns of North Korean influence in Cosmos Hub's LSM
  • Cosmos co-founder Jae Kwon alleges North Korean agents helped develop Cosmos Hub’s LSM code
  • Kwon accuses Iqlusion’s Zaki Manian of hiding unresolved security risks
  • Kwon urges an immediate audit and stricter oversight for future implementations

Cosmos co-founder Jae Kwon has raised serious concerns regarding the integrity of the Cosmos Hub’s liquid staking module (LSM), alleging that significant portions of its development involved individuals linked to North Korea.

In a statement released on Tuesday, Kwon accused Cosmos validator hosting firm Iqlusion and its leader, Zaki Manian, of “gross negligence” in allowing the module’s integration without adequate security vetting.

Cosmos Hub’s LSM developers North Korea agents

According to Kwon, development of the LSM began in August 2021 under the direction of Iqlusion and Manian, with contributions from developers Jun Kai and Sarawut Sanit.

Kwon alleges that these developers were later identified as North Korean agents and had provided a substantial portion of the module’s code.

Despite awareness of their connections since March 2023, Kwon claimed Manian withheld this information and failed to disclose several unresolved security risks associated with the LSM.

The controversy gained traction following Manian’s social media acknowledgement that he had known about the North Korean-linked developers for months. However, instead of taking preventive actions, such as conducting an additional audit or informing the Cosmos community, Kwon stated that Manian continued to assert the module was “ready to be deployed.”

Kwon accused Manian of a “profound breach of trust” for prioritizing deployment over community safety.

Critical vulnerabilities in the LSM

Security issues had already surfaced during a 2022 audit that revealed critical vulnerabilities in the LSM. These vulnerabilities were reportedly addressed by the same North Korean-linked developers.

Kwon suggested that despite Manian’s claim of rewriting the LSM code before deployment, significant risks persisted, especially since the module was not a standalone feature, but a set of modifications built atop existing Cosmos staking modules.

This could potentially expose all staked ATOM tokens to security threats.

Kwon has called on the Cosmos governance community to initiate a comprehensive audit of the LSM immediately. Additionally, he urged the Interchain Foundation to impose stricter auditing standards and create an oversight framework to ensure the security of future Cosmos implementations.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Internet Security

Six Egyptian Men Arrested Following Abduction and Sexual Assault Video

Security authorities in Giza have arrested six individuals, including five students and a delivery worker, following the viral spread of a social media video depicting the violent abduction of a young woman in broad daylight. Investigators tracked down the victim, who lives in the Al-Ahram area…

Security authorities in Giza have arrested six individuals, including five students and a delivery worker, following the viral spread of a social media video depicting the violent abduction of a young woman in broad daylight. Investigators tracked down the victim, who lives in the Al-Ahram area…
Read More

Continue Reading
Internet Security

PSA: In the latest GTA 6 leak’s aftermath, it’s not a good idea to download files with names like totallylegitgta6leakedbuild.exe

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy. Home News Grand Theft Auto VI PSA: In the latest GTA 6 leak’s aftermath, it’s not a good idea to download files with names like totallylegitgta6leakedbuild.exe Also beware anything dubbed certainlynotavirusthisisgta6myboy.exe Image credit: Rockstar Games

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy.

PSA: In the latest GTA 6 leak’s aftermath, it’s not a good idea to download files with names like totallylegitgta6leakedbuild.exe

Also beware anything dubbed certainlynotavirusthisisgta6myboy.exe

A drug deal in GTA 6.
Image credit: Rockstar Games

While scammers and other ne’er-do-wells leaning into the allure of playing GTA 6 as part of their efforts to spread malware isn’t anything new – cybersecurity companies have been issuing warnings about it for months – there appears to have been an uptick in such behaviour following the latest GTA 6 leak. With speculation rampant as to what exactly the hackers known as Cyberleek may have access to, now is not the time to be downloading any files claiming to be GTA 6.

(more…)

Continue Reading
Internet Security

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools…

Researchers scour social media to measure developer concerns about AI coding tools…
Read More

Continue Reading
Internet Security

Coldcard Hacker Gets Brazen Bitcoin Laundering Offer Onchain

The Coldcard security incident entered another chapter after a public bitcoin transaction offered laundering services to the thief behind one of the largest self-custody bitcoin thefts ever recorded, while users also reported emergency firmware updates leaving some hardware wallets unusable. The new developments come just days after Coinkite disclosed that a long-dormant firmware flaw had

The Coldcard security incident entered another chapter after a public bitcoin transaction offered laundering services to the thief behind one of the largest self-custody bitcoin thefts ever recorded, while users also reported emergency firmware updates leaving some hardware wallets unusable. The new developments come just days after Coinkite disclosed that a long-dormant firmware flaw had [……
Read More

Continue Reading