CryptoReal
CASE FILE — Oct 22, 2024

How Alleged North Korean Developers Helped Build the Cosmos Hub's Staking Module

A controversy engulfing the Cosmos Hub's Liquid Staking Module (LSM) has raised questions about whether alleged North Korean developers helped write core code now embedded in one of Cosmos' key infrastructure pieces, rather than the network being compromised through an external hack.

Credit: Jae Kwon, Jacob Gadikian, CoinDesk

01Background

The LSM, once regarded as a major achievement for Cosmos, is now at the center of a governance dispute involving allegations that developers linked to North Korea contributed substantially to its codebase. Jacob Gadikian, a former figure in the Cosmos ecosystem, wrote on X that the issue wasn't about the developers' geography or ethnicity, but that "the people who built the LSM are the world's most skilled and prolific crypto thieves."

02Timeline of events

  • August 2021: Development of the LSM begins. Iqlusion, led by Zaki Manian, starts building the module together with developers identified as Jun Kai and Sarawut Sanit.
  • July 2022: An audit by Oak Security identifies critical vulnerabilities in the LSM, notably around the potential for validators and stakers to evade slashing penalties. The same developers who wrote the original code are assigned to fix these issues.
  • December 4, 2022: The last code merge attributed to Jun Kai and Sarawut Sanit is submitted. The two developers then disappear from the project.
  • March 2023: The FBI reportedly contacts Zaki Manian directly, informing him of a suspected North Korean connection to the developers who had worked on the LSM. Manian does not share this information with the wider Cosmos community at the time.
  • April 3, 2023: Stride Labs takes over further LSM development, framed publicly as a rewrite that primarily adds security features.
  • April 7, 2023: Manian advocates for LSM integration on the Cosmos Hub Forum, describing the module as finished.
  • April 19, 2023: Governance Proposal #790 is submitted on-chain, without disclosure of the North Korean developer connection or any unresolved security concerns.
  • August 25, 2023: Proposal #821, a software upgrade proposal incorporating the LSM, is submitted.
  • September 2023: The LSM is officially integrated into the Cosmos Hub.
  • October 2, 2024: Manian publicly acknowledges on X that he had learned of the DPRK links back in March 2023.
  • October 15, 2024: Cosmos co-founder Jae Kwon publishes a detailed exposé alleging negligence in handling the known vulnerabilities and the developer connection, and calling for accountability.

03Key figures

Zaki Manian led Iqlusion and was the primary advocate pushing the LSM toward integration on the Cosmos Hub. He has acknowledged learning of the North Korean connection in March 2023 but did not disclose it publicly until October 2, 2024 — roughly a year and a half later.

Jae Kwon, a Cosmos co-founder, authored the October 15, 2024 exposé. He alleged that unresolved LSM vulnerabilities could put all staked ATOM at risk, called for immediate independent audits, and argued for blacklisting parties that continued to promote what he characterized as insecure protocols.

Jun Kai and Sarawut Sanit are named as the developers responsible for writing the majority of the LSM codebase. They were also the ones assigned to remediate the critical vulnerabilities flagged by the July 2022 Oak Security audit — the same code they had originally written. Both developers left the project after their final commit in December 2022 and have not resurfaced.

04The technical concern: slashing evasion

The LSM allows users to stake ATOM and receive a liquid staking token in return, letting them participate in DeFi while their underlying stake continues securing the network. The vulnerability identified by Oak Security centers on the possibility that holders could swap their liquid tokens back to ATOM quickly enough to exit before a slashing penalty is applied — a penalty meant to punish misbehaving validators and the stakers backing them.

If this evasion is possible in practice, other stakers backing the same validator would absorb losses that the liquid-token holder avoided. Critics argue this undermines a foundational assumption of Cosmos' proof-of-stake security model: that slashing risk keeps validators (and their delegators) honest. Reduced consequences for misbehavior could, in theory, encourage riskier validator behavior, network instability, and an erosion of trust that leads ATOM holders to exit.

05Fallout

The disclosures have generated significant disruption within the Cosmos community: diminished trust in project leadership, renewed calls for comprehensive code audits, contentious governance debate over the LSM's future on the Hub, and concern among some developers about continuing to build on the affected infrastructure.

06Broader context

The episode follows closely on the heels of Tapioca's $4.4 million loss, adding to a pattern of incidents tied to North Korea-linked actors infiltrating crypto projects not through traditional exploits but through employment and contribution to codebases themselves. Related reporting has pointed to other vectors of this kind of infiltration, including compromised VS Code extensions and infiltration of developer hiring pipelines. The Cosmos LSM case illustrates that security reviews focused solely on smart contract code may be insufficient if the developers writing that code cannot be reliably vetted.

CosmosEspionage
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.