Security Researcher Discloses CometBFT 0-day Vulnerability; Direct Asset Theft Not Possible

ATOM0.12%

Gate News message, April 21 — Security researcher Doyeon Park disclosed a critical 0-day vulnerability (CVSS 7.1) in CometBFT, the consensus layer of Cosmos, according to a post on X. The flaw could cause network nodes to stall during block synchronization, disrupting system operations, but cannot directly result in asset theft.

Park stated he attempted to follow coordinated vulnerability disclosure (CVD) procedures; however, due to the project's lack of cooperation and "irresponsible decisions," he chose to publicly release vulnerability details. Park emphasized that any resulting security risks will be the responsibility of the affected projects.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments