White Hat Researcher Reveals Cosmos 0-Day Bug, Accuses Team of Ignoring PoC and Marking Report as Spam

White Hat Researcher Reveals Cosmos 0-Day Bug, Accuses Team of Ignoring PoC and Marking Report as Spam

N
News Editor 01
2026-07-23 06:00:14
Security researcher Doyeon Park disclosed a critical 0-day vulnerability in Cosmos' CometBFT consensus layer that can deadlock nodes. He slammed officials for ignoring proof-of-concept, downgrading severity to dodge bounty, and marking his report as spam.
CosmosCometBFT0-daywhite hatsecurity disclosure

A security researcher has gone public with a 0-day vulnerability in the CometBFT consensus layer of Cosmos, accusing the project's team of negligence and deliberate downplaying. Doyeon Park published a detailed thread on X, warning that the bug could cause node deadlocks during block sync.

High-Severity Bug Risks Network Paralysis

The vulnerability carries a CVSS score of 7.1 (High). While it cannot directly steal user funds, it can bring the network to a halt. Park issued an urgent "Validator Survival Guide", urging node operators to avoid restarting nodes until a patch is released. "Nodes in consensus can operate normally, but if restarted and entering block sync phase, the bug can be triggered, causing a deadlock that prevents the node from ever rejoining," he explained.

Allegations of Willful Ignorance and Bounty Avoidance

Park said he attempted responsible disclosure through the CVD process but was forced to blow the whistle after two months of dismissive behavior. Specific grievances include: Ignoring proof-of-concept: After his initial report in February, the team told him to file a public GitHub issue, claiming the attack wasn't feasible. When Park provided a network-level PoC that refuted their claim, they stopped responding. Downgrading severity: Officials reclassified a related 1-day vulnerability (CVE-2025-24371) as "informational" despite MITRE and CVSS ratings, a move Park says was aimed at avoiding bounty payouts. Spam-labeling his report: In March, a separate and more severe bug report filed via HackerOne was marked as spam without any technical review. Even after the SEAL 911 security team intervened, the official stance remained unchanged.

Whistleblowing for Ecosystem Transparency

On April 21, Park released technical details and a video demonstration (without full exploit code). "The goal is to protect the ecosystem, not harm it. All safety risks are entirely the vendor's fault," he stated.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.