Cosmos co-founder Jae Kwon has publicly accused Zaki Manian and his validator and infrastructure firm Iqlusion of exposing the Cosmos Hub to serious security risks by allowing developers allegedly linked to the North Korean state to build key parts of its Liquid Staking Module (LSM). Kwon’s allegations center on claims that two core LSM contributors, identified as Jun Kai and Sarawut Sanit, were in fact North Korean agents, and that Manian learned of their DPRK ties from the FBI in March 2023 but did not promptly disclose this to the Cosmos community or initiate sufficient additional security review. Instead, Kwon says, Manian continued to present the LSM as ready for deployment despite earlier audits already flagging serious issues. According to reporting and community analyses, the LSM—introduced to let Cosmos Hub stakers “re-stake” ATOM via liquid staking providers—was largely developed under Iqlusion’s lead from August 2021 onward, with Oak Security’s 2022 audit identifying critical vulnerabilities including potential ways for stakers to evade slashing, which undermines core staking security assumptions. Kwon and other Cosmos contributors now characterize the situation as a supply-chain style attack on the Cosmos Hub codebase, arguing that North Korean-linked developers may have inserted or left behind subtle vulnerabilities, and that some SDK branches are already “infected.” In response, Cosmos ecosystem developers and governance participants are moving to remove or deprecate the LSM, push for a comprehensive security review of all code written by the implicated developers, and consider governance actions such as blacklisting those involved and demanding clarity from the Interchain Foundation on what it knew and when. The dispute has broad implications for the Cosmos ecosystem and open-source blockchain development more generally. The incident highlights how deeply nation-state–linked actors can embed themselves not just in user-facing infrastructure but in protocol-level code, raising concerns that code contributions can be weaponized as much as traditional exploits. It has also intensified scrutiny of operational security and disclosure practices among key Cosmos stakeholders, as critics argue that failing to promptly reveal the FBI warning and the developers’ alleged North Korean military ties deprived validators, token holders, and integrators of crucial risk information. Governance discussions now focus on stronger due diligence on core developers, better audit processes, and more transparent incident reporting to reduce the likelihood that politically sanctioned or hostile actors can quietly shape critical blockchain infrastructure over extended periods.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on North Korea

Comments