Interchain Labs says former Cosmos maintainers unknowingly onboarded North Korea-linked actor, finds no security issues and doubles bounty

Interchain Labs has confirmed that an individual later identified as being linked to North Korea contributed to Cosmos repositories while employed by former maintainers between 2022 and 2024.

The Cosmos core developer, in collaboration with the Security Alliance and Asymmetric Research, published a security report confirming that this individual had limited access to two repositories: cosmos/IAVL and cosmos/cosmos-sdk. The review found that most of the code he contributed was deprecated or excluded from the roadmap following the cancellation of SDK v2, and independent audits found no remaining risks or vulnerabilities.

However, to support transparency, ICL is offering double bounty rewards on the Cosmos HackerOne page for the next month for discovering any qualifying vulnerabilities tied to the actor’s GitHub account, “cool-develope.”

More specifically, the individual worked for former core stack maintenance vendors from mid-2022 until November 2024, before ICL’s formation and the end of Cosmos’ third-party maintenance model. After ICL took over all core stack development, new security and hiring protocols were implemented, which uncovered the issue and blocked further contributions, it said in a statement shared with The Block. The same individual later reapplied for a position but was flagged and rejected.

Since February, ICL said it has implemented sweeping security upgrades across all core Cosmos repositories, including revoking legacy access, re-permissioning all contributors, rotating credentials, and tightening audit controls.

“Incidents like this showcase the urgent need for more widely adopted and rigorous security procedures, not just within the Web3 ecosystem but across the broader tech landscape,” Interchain Labs co-CEO Barry Plunkett said. “Transparency and security are our top priority within the Cosmos ecosystem. Since unifying the development of the Cosmos Stack under ICL this year, we’ve updated and enforced rigorous security standards across the stack. This enabled us to prevent any further contributions from the individual involved under our leadership. While we have found no indication of malicious code contributed by the DPRK actor, we are incentivizing further community review through our bounty program, and will be completely deprecating the codebase through our planned release of IAVL v2 which is a full rewrite.”

ICL stated that centralizing all Cosmos Stack contributions under Interchain Labs has enabled the Foundation to apply consistent security practices and HR protocols, thereby reducing its reliance on third parties with varying risk tolerances.

“This case serves as a reminder that open-source ecosystems require proactive, continuous security,” Asymmetric Research CEO Jonathan Claudius said. “Cosmos isn’t the first ecosystem to be infiltrated by malicious actors and won’t be the last. Transparency not only builds trust, but surfaces lessons that others can apply to strengthen their own systems. These learnings benefit the broader ecosystem and reinforce the importance of layered, collaborative defense strategies. An intensified focus on proactive security, along with initiatives such as the Security Alliance, will help make the web3 space stronger and more resilient.”

Not the first DRPK-linked actor to infiltrate Cosmos

In October, Cosmos co-founder Jae Kwon raised separate concerns about the integrity and security of Cosmos Hub’s liquid staking module, stating that a significant part of its development had been carried out by individuals later identified as North Korean agents.

“For sixteen months, the LSM was developed by individuals linked to North Korea, and their contributions were integrated into the Cosmos Hub without proper security vetting,” Kwon said at the time, blaming the “gross negligence” of Cosmos-based development firm Iqlusion and its leader, Zaki Manian.

Iqlusion began developing the LSM in 2021 with Jun Kai and Sarawut Sanit, who Kwon later alleged were North Korean agents. While a 2022 audit discovered critical vulnerabilities, the same developers were reportedly tasked with fixing them. Kwon claimed their final code merge was retained. Manian, however, said the code was rewritten before deployment in collaboration with staking firm Stride.

© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

 

Icon Bitcoin Cryptocurrency

Trade Crypto On Coinhub Exchange

Trade Crypto On Coinhub Exchange

Stay ahead of the market by turning news insights into trading opportunities. With Coinhub Exchange, you can seamlessly buy, sell, and manage your digital assets, all in one secure platform. Take advantage of real-time market insights, deep liquidity, and fast execution for your favorite cryptocurrencies. Don’t just read about it — trade crypto now!

Disclaimer

The content of this article shown by Coinhub News, powered by The Block, is for informational purposes only and should not be construed as financial, legal, tax, or investment advice. Coinhub News and its affiliates are not a licensed financial advisor, legal advisor, broker, or tax advisor, and ... should not be considered as professional advice or a recommendation to engage in any specific investment, legal decision, or financial transaction. Cryptocurrency markets are highly speculative and volatile. Readers should perform their own independent research and consult with a qualified professional before making any financial or legal decisions. The opinions expressed in this article are those of the author and do not necessarily represent the views or opinions of the Company of its affiliates. Additionally, the Company does not make any representations or warranties regarding the accuracy, timeliness, reliability, or completeness of any information in this article. By accessing this content, you acknowledge that any reliance on the information contained in this article is solely at your own risk. The Company is not responsible for any financial losses, legal disputes, or other damages that may arise from reliance on this content or from any investment or legal decisions based on the information provided. Investing in cryptocurrencies involves substantial risks, including the risk of losing your entire investment, and you should carefully consider whether it is appropriate for your circumstances.

Read more

💹 Related News

🔥 Popular News

Referral Reward Program – Earn Commissions!  Learn More Icon Long Arrow