Security researcher publicly discloses CVSS 7.1 zero-day in CometBFT consensus layer causing node stalls during sync on chains securing $8B+ in assets.
Security & Exploits ·
A security researcher has publicly disclosed a zero-day vulnerability in CometBFT, the consensus layer underlying the Cosmos ecosystem. The flaw carries a CVSS severity rating of 7.1 and can cause nodes to stall during block synchronization across chains that collectively secure over $8 billion in assets. The researcher emphasized that while the vulnerability disrupts node operations, it does not enable direct theft of assets.
The researcher stated that an attempt to follow Coordinated Vulnerability Disclosure protocols was made, but proceeded with public disclosure citing the vendor's lack of cooperation and what was characterized as irresponsible decisions. The disclosure included notice that detailed vulnerability information would be shared alongside criticism of the vendor's handling of the issue. Validators have been advised to avoid restarting nodes, as doing so could trigger entry into the vulnerable synchronization phase.
The disclosure was made unilaterally without apparent advance coordination with affected chain operators or a unified patch release timeline, leaving the scope and timeline for remediation across the ecosystem unclear.