Bounty: $4000 identify the person or persons who attacked the cosmos hub
it is of vital importance to actually address security issues Cosmos chain teams sabotage @cosmoshub in order to gain competitive advantage, with the tacit blessing of @interchain_io and its contractors, here’s proof: two weeks before the incident, they cosmos hub was running IBC v3.0..0 on mainnet >6mos after v3.0.0 was retracted for security issues. And I told @buchmanster , @JTremback , other members of informal hub team, and the full ibc team about the issue >2wks before the exploit and I cited that the @quicksilverzone launch was at risk. To my knowledge, this has not ever been reported to police by @interchain_io , and I think that’s unacceptable. If you think that’s acceptable, that’s your choice, but that means I do not want to work with you, or anywhere near you, so this is my litmus test. I was asked not to tell anyone by @JTremback and @buchmanster . I told no one, including quicksilver whose launch I could have saved. No one. Then it got exploited. Teams sabotage the hub to gain a competitive advantage , here are the tx details: delegate address: cosmos13dqvh4qtg4gzczuktgnw8gc2ewnwmhdwnctekxctyr4azz4dcyysecgq7e tx that shafted us up the…
Excerpt (1190 of 4159 characters). Read the whole post on the forum ↗
Yeah it’s really not normal, except of course in Cosmos, where unfortunately we don’t seem to investigate stuff even though we should.
bro, while I hope you find the one who did that, I doubt the aforementioned teams are interested in helping you. after all, the same ppl have been draining funds via juno and other slow rugpull projects for years
I got these questions from a friend, answers are mine • What exactly was the vulnerability? The cosmos hub was using a version of IBC that was deprecated due to dragonberry and using module account names as the basis of module account addresses, deterministically. • How was it exploited? The module account address could be predicted by hashing the name of the module account. The attacker predicted this, and sent 1uatom into the ica, so when quicksilver connected to the hub, user funds got stuck when users tried to use quicksilver. • What was the financial or operational impact to Quicksilver? Be specific. It was devastating. Go to market is extremely sensitive, and Cosmos Hub team members referred to this as a Quicksilver issue. It was not. The Hub was simply not maintained, resulting in this issue. The reality is that Quicksilver is a product that was made for the cosmos Hub. This is why it is increasingly difficult to recommend Cosmos. Apparently, Cosmos teams compete by hacking. Liquid staking in Cosmos was always very competitive. The transactions mentioned lack clear chronology or linkage to an exploit scenario. We now have an illustration, but…
Excerpt (1198 of 2011 characters). Read the whole post on the forum ↗