tendermint

2 articles
Sort: New Top Best
clear filter
0 8/10
vulnerability

A critical vulnerability in Axelar Network allowed attackers to force validators to miss votes by crafting transactions with excessive logs that exceed Tendermint's 1MB RPC request limit, leading to automatic Chain Maintainer deregistration and potential halt of cross-chain operations. The vulnerability has been patched via governance proposal 256 disabling the auto-deregistration mechanism.

Axelar Network Marco Hextor Immunefi AxelarGateway Tendermint Cosmos SDK governance-proposal-256
marcotnunes.com · Marco Nunes · 4 hours ago · details
0 8/10
bug-bounty

Researcher disclosed two critical bugs in Sei Network's Cosmos blockchain: (1) an ABCI EndBlocker panic triggered via vesting accounts that would halt the chain, and (2) a balance transfer vulnerability in EVM integration allowing arbitrary fund transfers. Both were caught pre-mainnet and awarded $75k and $2M respectively.

Sei Network Sei Foundation Cosmos SDK Geth Trail of Bits Immunefi CVE-2024-XXXXX (implied but not stated)
usmannkhan.com · usmannk · 4 hours ago · details