Cosmos-SDK & IBC Vulnerability Retrospective: Security Advisories Dragonberry and Elderflower (October 2022)
On October 8, 2022, a small group of Cosmos engineers led by Dev Ojha ( @Valardragon ) of Osmosis began an intensive security review of the ICS-23 implementation. This review took place as a response to the BSC incident that impacted Binance Chain on October 7, 2022, and focused on areas where ICS-23 interfaces with proofs generated by the IAVL Merkle tree used by the Cosmos SDK . As a result of this bug hunt, two separate security vulnerabilities were identified in the Cosmos stack. • The first vulnerability, Dragonberry , originated in ICS-23 (IBC) and enabled the forgery of IBC timeouts. Timeout forgeries could be escalated to ICS-20 doublespend. • The second vulnerability, Elderflower , originated in Authz (Cosmos-SDK) and enabled bypassing parts of the Cosmos SDK message authentication system.This authentication bypass could potentially be escalated to inflation, theft, or other exploits depending on chain-specific implementation details. These vulnerabilities were patched when core devs across IBC-connected chains distributed the Dragonberry patch for Cosmos SDK. In this post, we would like to provide details about both incidents as well as the next steps for the…
Excerpt (1197 of 10847 characters). Read the whole post on the forum ↗
![]()
typically, something like this is found after an exploit
many thanks to everyone who worked to identify aqnd patch this issue before it was exploited, and to the 60 or so chain teams that got patched code running and released, and the 300ish ecosystem validators who applied the patched code.
I think that we accomplished something truly special here.
Thanks for everyone’s hard work
Woot woot. Thanks peeps. Good job