Gate News message, April 21 — Security researcher Doyeon Park disclosed a critical 0-day vulnerability (CVSS 7.1) in CometBFT, the consensus layer of Cosmos, according to a post on X. The flaw could cause network nodes to stall during block synchronization, disrupting system operations, but cannot directly result in asset theft.
Park stated he attempted to follow coordinated vulnerability disclosure (CVD) procedures; however, due to the project's lack of cooperation and "irresponsible decisions," he chose to publicly release vulnerability details. Park emphasized that any resulting security risks will be the responsibility of the affected projects.