Lune

USENIX Security2026Top-tier venue

The Perils of Flexibility: Uncovering Application-Layer Vulnerabilities in Cosmos SDK Customization Points

Pengxiang Ma, Ningyu He, Zhongchun Cao, Zihao Li, Xiapu Luo

2026Year

Abstract

The Cosmos SDK is a premier blockchain development framework that facilitates the construction of application-layer logic through reusable modules and extensible customization interfaces. Currently, the Cosmos ecosystem encompasses over one hundred production blockchains, reaching a peak total market capitalization exceeding 32billion.Whilethismodulararchitecturesignificantlylowersdevelopmentbarriers,itsimultaneouslyexpandstheapplication−layerattacksurface,asdeveloper−accessiblecustomizationpointsaresusceptibletomisuseorincorrectcomposition.Inthiswork,wepresentasecurityanalysisofapplication−layerpitfallswithinCosmos−basedblockchains.Byanalyzingthetransactionexecutionlifecycleanddeveloper−accessiblecustomizationpoints,weformalizefourexecutioninvariantsessentialforcorrecttransactionprocessing.Guidedbytheseinvariants,weidentifyeightrecurringclassesoferror−pronedevelopmentpatternsinwhichviolationscompromisetransactionsafety,resultinginsevereconsequencesrangingfromassetthefttochain−haltingfailures.Toassesstheprevalenceandimpactofthesepitfalls,weconductedanecosystem−wideempiricalanalysis,uncovering65vulnerabilitiesacrossvariousCosmos−basedblockchains.Followingresponsibledisclosure,26ofthesevulnerabilitieswereacknowledgedbytheaffectedprojectteams,with19subsequentlyreceivingpublicfixesandtworesultinginassignedCVEidentifiers.Thesedisclosuresyielded32 billion. While this modular architecture significantly lowers development barriers, it simultaneously expands the application-layer attack surface, as developer-accessible customization points are susceptible to misuse or incorrect composition. In this work, we present a security analysis of application-layer pitfalls within Cosmos-based blockchains. By analyzing the transaction execution lifecycle and developer-accessible customization points, we formalize four execution invariants essential for correct transaction processing. Guided by these invariants, we identify eight recurring classes of error-prone development patterns in which violations compromise transaction safety, resulting in severe consequences ranging from asset theft to chain-halting failures. To assess the prevalence and impact of these pitfalls, we conducted an ecosystem-wide empirical analysis, uncovering 65 vulnerabilities across various Cosmos-based blockchains. Following responsible disclosure, 26 of these vulnerabilities were acknowledged by the affected project teams, with 19 subsequently receiving public fixes and two resulting in assigned CVE identifiers. These disclosures yielded 51,000 in bug bounty rewards and prevented potential asset theft affecting assets valued in the tens of millions of dollars. Our findings demonstrate that application-layer vulnerabilities are widespread in the Cosmos ecosystem and underscore the critical need for increased rigor in application-layer design, development, and auditing.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 67efef4e-e515-4d01-a55c-ad6871372739

Builds on13

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines