Security researcher reveals high-severity zero-day in Cosmos CometBFT
A security researcher has publicly detailed a previously unknown flaw in Cosmos' consensus layer, CometBFT, according to CoinDesk. Doyeon Park wrote on X that the issue carries a CVSS score of 7.1 (High) and could cause nodes across the Cosmos ecosystem to stall during block synchronization, though it does not enable direct theft of assets. The Cosmos ecosystem secures more than $8 billion in assets.
Park said they initially followed a Coordinated Vulnerability Disclosure (CVD) process to minimize risk to the network. They ultimately moved to a public disclosure, citing a lack of cooperation from the vendor and what they described as irresponsible decision-making, and said the decision aligned with the vendor's final determination.