|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
ワームホール プロトコルに貢献している非対称リサーチ社は、Cosmos ブロックチェーン エコシステムに 1 億 5,000 万ドル以上を侵害する可能性がある「リエントランシーの脆弱性」を発見しました。 Cosmos のバグ報奨金プログラムを運営する Asymetric and Amulet によると、バグの深刻さにも関わらず、悪用が行われる前に非公開で公開され、パッチが適用されました。

Cosmos Blockchain Bug Patched, Preventing Potential $150 Million Loss
Cosmos Blockchainのバグがパッチされ、1億5,000万ドルの損失の可能性を回避
Asymmetric Research, a security firm actively contributing to the Wormhole interoperability protocol, has uncovered a critical vulnerability within the Cosmos blockchain ecosystem. This reentrancy bug, if exploited, could have potentially compromised over $150 million worth of digital assets.
ワームホールの相互運用性プロトコルに積極的に貢献しているセキュリティ会社である非対称リサーチは、Cosmos ブロックチェーン エコシステム内の重大な脆弱性を発見しました。この再入バグが悪用された場合、1 億 5,000 万ドル以上相当のデジタル資産が侵害される可能性があります。
Prompt Action Averts Disaster
迅速な行動で災害を回避
Asymmetric responsibly disclosed the vulnerability to the Cosmos development team, who promptly addressed the issue before any malicious actors could take advantage. "We privately disclosed the vulnerability through the Cosmos HackerOne Bug Bounty program and the issue is now patched," Asymmetric stated in an official release. "No malicious exploitation took place and no funds were lost."
Ametric は責任を持ってこの脆弱性を Cosmos 開発チームに開示しました。Cosmos 開発チームは、悪意のある攻撃者が悪用する前に直ちに問題に対処しました。 「我々はCosmos HackerOne Bug Bountyプログラムを通じてこの脆弱性を非公開で公開し、現在この問題はパッチされている」とAmetricは公式リリースで述べた。 「悪意のある搾取は行われず、資金の損失もありませんでした。」
Jessy Irwin, CEO of Amulet, an organization contracted by the Interchain Foundation to oversee the bug bounty program and coordinate security for the Cosmos ecosystem, confirmed the report and the subsequent release of an advisory notice.
バグ報奨金プログラムを監督し、Cosmos エコシステムのセキュリティを調整するために Interchain Foundation と契約した組織である Amulet の CEO、Jessy Irwin 氏は、この報告書とその後の勧告通知のリリースを認めました。
A First for Cosmos
コスモス初
The Cosmos ecosystem encompasses a network of blockchains that share common code and core modules. While no funds were lost due to this bug, its discovery marks a significant milestone for the ecosystem. It represents the first instance of a reentrancy vulnerability being identified within Cosmos, a platform widely regarded as one of the most secure blockchain technologies.
Cosmos エコシステムには、共通のコードとコア モジュールを共有するブロックチェーンのネットワークが含まれています。このバグによる資金の損失はありませんでしたが、このバグの発見はエコシステムにとって重要なマイルストーンとなりました。これは、最も安全なブロックチェーン テクノロジーの 1 つとして広く認められているプラットフォームである Cosmos 内でリエントランシーの脆弱性が確認された最初の例です。
Inter-Blockchain Communication Vulnerability
ブロックチェーン間通信の脆弱性
A key component of most Cosmos chains is the Inter-Blockchain Communication Protocol (IBC), a technology facilitating seamless communication and asset transfer between blockchains. Asymmetric's vulnerability discovery was specifically within ibc-go, a reference implementation of IBC utilized by numerous Cosmos chains.
ほとんどの Cosmos チェーンの重要なコンポーネントは、ブロックチェーン間のシームレスな通信と資産転送を促進するテクノロジーであるブロックチェーン間通信プロトコル (IBC) です。 Ametric の脆弱性の発見は、特に、数多くの Cosmos チェーンで利用されている IBC のリファレンス実装である ibc-go 内で行われました。
"During the investigation of this issue, both Amulet and the IBC-go team independently assessed the potential impact to identify parties at risk and mitigate the severity," Irwin explained.
「この問題の調査中に、アミュレットとIBC-goチームの両方が、リスクにさらされている当事者を特定し、深刻さを軽減するために潜在的な影響を独自に評価しました」とアーウィン氏は説明しました。
Infinite Token Minting Threat
無限トークン鋳造の脅威
The vulnerability, categorized as a reentrancy bug, theoretically enabled an attacker to mint an infinite number of tokens on IBC-connected chains such as Osmosis, which hosts one of the largest decentralized finance (DeFi) ecosystems on Cosmos.
この脆弱性はリエントランシーバグとして分類されており、理論的には攻撃者がCosmos上で最大規模の分散型金融(DeFi)エコシステムの1つをホストするOsmosisなどのIBCに接続されたチェーン上で無限の数のトークンを鋳造することを可能にした。
"While this vulnerability has been present in ibc-go since its inception, it only became exploitable due to recent developments in the Cosmos SDK ecosystem," Asymmetric revealed in a blog post. The vulnerability was triggered by the emergence of "IBC middleware," third-party applications built using CosmWasm, a WebAssembly-based smart contract runtime, that enables cross-blockchain token usage.
「この脆弱性は当初からibc-goに存在していましたが、Cosmos SDKエコシステムの最近の開発により悪用可能になったばかりです」とAsymetricはブログ投稿で明らかにした。この脆弱性は、クロスブロックチェーントークンの使用を可能にする、WebAssembly ベースのスマートコントラクトランタイムである CosmWasm を使用して構築されたサードパーティアプリケーションである「IBC ミドルウェア」の出現によって引き起こされました。
Highlighting Cross-Chain Security Risks
クロスチェーンのセキュリティリスクを強調する
"This vulnerability emphasizes the urgent need for intensified research into cross-chain security risks to safeguard the multichain ecosystem," remarked Jonathan Claudius, CEO of Asymmetric and former security chief at venture firm Jump Crypto. "This case demonstrates our commitment to identifying and neutralizing existential threats that could jeopardize the digital economy."
「この脆弱性は、マルチチェーンのエコシステムを保護するためにクロスチェーンのセキュリティリスクに関する研究を強化する緊急の必要性を強調しています」と、アシンメトリック社の CEO であり、ベンチャー企業ジャンプ クリプトの元セキュリティ責任者であるジョナサン クラウディウス氏は述べています。 「この訴訟は、デジタル経済を危険にさらす可能性のある実存的な脅威を特定し、無力化するという当社の取り組みを示しています。」
Conclusion
結論
The swift and effective response by Asymmetric Research and the Cosmos development team averted a potentially catastrophic loss of funds within the Cosmos blockchain ecosystem. This incident highlights the importance of continuous vulnerability monitoring and responsible disclosure practices within the blockchain industry. It also underscores the need for ongoing research into cross-chain security risks to ensure the resilience and security of the evolving multichain ecosystem.
アシンメトリーリサーチとコスモス開発チームによる迅速かつ効果的な対応により、コスモスブロックチェーンエコシステム内の壊滅的な資金損失の可能性が回避されました。この事件は、ブロックチェーン業界における継続的な脆弱性監視と責任ある開示慣行の重要性を浮き彫りにしました。また、進化するマルチチェーン エコシステムの回復力とセキュリティを確保するために、クロスチェーンのセキュリティ リスクに関する継続的な研究の必要性も強調しています。
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































