A critical vulnerability in Cosmos’s Inter-Blockchain Communication (IBC) stack was disclosed after Asymmetric Research found that a timeout-handling reentrancy issue in ibc-go could let an attacker replay the same failure path and potentially redeem or mint an unlimited number of IBC tokens. The issue affected IBC middleware used with CosmWasm-based chains and was serious enough that Cosmos teams privately patched major networks before the disclosure became public. The core risk was that the OnTimeout callback could be recursively invoked before packet commitments were fully cleared, creating a path to double-spend escrowed funds or create unexpected token inflation on vulnerable chains. Cosmos said chains were considered safe once at least one-third of voting power had applied the patch, though teams were urged to upgrade as quickly as possible; the vulnerability was reportedly fixed without any known malicious exploitation or loss of funds.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on IBC

Comments