Gate News message, April 22 — Security researcher Doyeon Park disclosed a critical CVSS 7.1 zero-day vulnerability in Cosmos' consensus layer CometBFT that could cause nodes to freeze during block synchronization, potentially affecting networks securing over $8 billion in assets. The vulnerability cannot directly steal funds.
Park initiated a coordinated disclosure process on February 22 but encountered resistance from the vendor, who requested public GitHub issue submission while refusing public disclosure. On March 4, HackerOne marked his second report as spam. On March 6, the vendor arbitrarily downgraded a related vulnerability (CVE-2025-24371) to "informational" level, dismissing international standards. Park submitted a network-level proof-of-concept to counter this decision before publicly disclosing the flaw on April 21.
Park recommends that Cosmos validators avoid restarting nodes before a patch is released. Nodes already in consensus mode can continue operating, but restarting and entering synchronization may expose them to attacks from malicious peers, potentially causing deadlock.