A security researcher has gone public with a 0-day vulnerability in the CometBFT consensus layer of Cosmos, accusing the project's team of negligence and deliberate downplaying. Doyeon Park published a detailed thread on X, warning that the bug could cause node deadlocks during block sync.
High-Severity Bug Risks Network Paralysis
The vulnerability carries a CVSS score of 7.1 (High). While it cannot directly steal user funds, it can bring the network to a halt. Park issued an urgent "Validator Survival Guide", urging node operators to avoid restarting nodes until a patch is released. "Nodes in consensus can operate normally, but if restarted and entering block sync phase, the bug can be triggered, causing a deadlock that prevents the node from ever rejoining," he explained.
Allegations of Willful Ignorance and Bounty Avoidance
Park said he attempted responsible disclosure through the CVD process but was forced to blow the whistle after two months of dismissive behavior. Specific grievances include: Ignoring proof-of-concept: After his initial report in February, the team told him to file a public GitHub issue, claiming the attack wasn't feasible. When Park provided a network-level PoC that refuted their claim, they stopped responding. Downgrading severity: Officials reclassified a related 1-day vulnerability (CVE-2025-24371) as "informational" despite MITRE and CVSS ratings, a move Park says was aimed at avoiding bounty payouts. Spam-labeling his report: In March, a separate and more severe bug report filed via HackerOne was marked as spam without any technical review. Even after the SEAL 911 security team intervened, the official stance remained unchanged.
Whistleblowing for Ecosystem Transparency
On April 21, Park released technical details and a video demonstration (without full exploit code). "The goal is to protect the ecosystem, not harm it. All safety risks are entirely the vendor's fault," he stated.

