Important Crypto.org Chain Security Update (13 April 2021)
Welcome to join our newsletter!
Recently, we have released our new binary of v.1.2.1 for Crypto.org mainnet. Aside from several improvements been made, this version is based on the upstream release of Cosmos SDK 0.42.4, where the following are some main issues that have been fixed:
Fixed a security issue with Tendermint:
Fixed a moderate severity security issue, Security Advisory Alderfly, which impacts all networks that rely on Tendermint light clients.
Made a small change on Go API-breaking to reduce panics in the RPC layer.
Added ledger/multisig detection in SignTx functions
The Module account has been fixed and user funds are more secure now with less vulnerability which may result in a chain halt.
Fixed security vulnerability identified in x/bank.
If the chain halts before or during the upgrade, validators with sufficient voting power need to upgrade and come online in order for the chain to resume. Since Cosmos SDK 0.42.3, the security patch for this issue has been added.
We recommend all users upgrade to the latest version that provides the latest features, security updates, and bug fixes. Here is the tutorial link that users can follow to complete the upgrade.
For further questions, please reach out to us at Discord or [email protected]. We sincerely thank you for your support.
The Crypto.org Chain Team