IBC had a close call with a critical vulnerability

The vulnerability enabled exploiters to replay a bug that would enable an infinite number of IBC tokens to be redeemed

article-image

Artwork by Crystal Le

share

A recent blog post by Asymmetric Research revealed there was a critical vulnerability that affected the inter-blockchain communication (IBC) protocol — a standard that enables interaction among individual cosmos chains.

This vulnerability was found specifically in ibc-go, the Golang high-level programming language implementation of the IBC protocol, and affected CosmWasm-based IBC middleware. 

IBC middleware was created to enable the integration of ICS20 with other IBC protocols. Similar to many bridging protocols, the middleware enables packets to be sent from one blockchain to another. These packets are stored as commitments before being properly received and deleted. If they are not received, tokens will be refunded through a timeout functionality. 

Read more: Picasso connects Ethereum to Cosmos IBC

Asymmetric Research found that the flow between the module deleting the commitment control could be replayed, which meant it was possible to replay the bug and exploit an infinite number of IBC tokens. 

Multiple chains were vulnerable to the issue, with Osmosis, one of the largest cross-chain DEXs in the Cosmos ecosystem, being the largest chain that could have been affected. However, due to rate limiting on the chain, the damage the bug could have potentially caused was limited. 

According to Asymmetric Research, the vulnerability has been privately disclosed to the Cosmos HackerOne bug bounty program, and the issue itself has been resolved without any malicious exploitation. 

Read more: Helpful hackers net more than $640k in 1 year with crypto bug bounties

“This issue demonstrates how easy it is to break trust assumptions and introduce new vulnerabilities by adding new features and functionality. It is also another example of the importance of defense-in-depth,” Asymmetric Research wrote in a blog post.

The research noted specifically that Cosmos teams had strong security measures in place that could have saved them from existential risks. 

“A binary patch was released to fix the underlying IBC timeout reentrancy without breaking consensus. Contributors spent much time and effort assessing the security implications of the mentioned issues,” Asymmetric Research wrote.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template.png

Research

The march toward an interoperable and onchain-by-default internet depends on reliable messaging and value transfer across heterogeneous domains. Crosschain protocols now process >$1.3T in combined annual transfer volume and secure tens of millions of user interactions, yet no single design dominates.

article-image

As the shutdown enters its second week, sources say the Senate Banking Committee looks to move ahead with a market structure bill markup

article-image

The collaboration expands Ripple’s Middle East footprint, supporting Bahrain’s blockchain adoption and future rollout of Ripple USD

by Blockworks /
article-image

The medical device firm will manage its $400 million Solana holdings using Coinbase Prime infrastructure to bolster its digital asset strategy

by Blockworks /
article-image

The deal gives PayPay a 40% stake in Binance Japan, linking digital assets with Japan’s largest mobile payment network

by Blockworks /
article-image

Citigroup’s venture arm backs BVNK to expand stablecoin payments infrastructure amid growing US regulatory clarity

by Blockworks /
article-image

The partnership integrates Deutsche Bank’s payment rails with Bullish’s regulated exchange, streamlining fiat operations for institutional traders

by Blockworks /