🚨 Halborn Discovers Zero-Day in CosmWasm 🚨
Read below for a 🧵 on our zero-day vulnerability in @CosmWasm smart contracts across 20+ blockchains…
1/ Last month, Halborn security researcher @OwlAtNite discovered a #zeroday vulnerability from the lack of normalization of addresses in Bech32 specification (a format for SegWit addresses) in #CosmWasm.
2/ This critical vulnerability allows an attacker to bypass validity checks or break storage keys🔑 under certain conditions.
3/ Because smart contracts based on CosmWasm are deployed on 20+ blockchains, this zero-day discovery potentially affects all CosmWasm-based contracts that perform comparisons or other operations based on account addresses.
4/ Read the full details of the technical details of the vulnerability on our blog: halborn.com/halborn-discov…
5/ Halborn is working closely with @confio_tech on remediation. Today, Confio announced the release of a patch for the vulnerability, which was audited by Halborn’s blockchain security experts.
6/ For detailed info on @CosmWasm’s patch notes, check out their tweet 🧵 :