Cosmos-Based Juno Blockchain Pushed Offline in Apparent Attack

A malicious smart contract has put the network out of commission for over 24 hours and comes less than a month after a controversial governance vote.

AccessTimeIconApr 6, 2022 at 11:59 p.m. UTC
Updated Apr 7, 2022 at 2:24 p.m. UTC

Sam is a reporter at CoinDesk focused on decentralized technology, DeFi and DAOs. He owns ETH, BTC and MATIC.

Cosmos-based blockchain Juno went offline on Tuesday as the result of a suspected attack on the network.

The network remains offline as of press time, but no user funds have been impacted and the Juno core development team says a fix is in the works, according to a retweet from the project’s official Twitter handle.

A Juno core developer speaking to CoinDesk on the condition of anonymity said the network crash stemmed from a malicious smart contract masked to look like a simple “hello world” program.

The suspected attacker sent a string of over 400 transactions to the smart contract over the course of three days in a process of apparent trial and error – eventually landing on a specific combination of transactions that crashed the network.

According to the developer who spoke with CoinDesk, the attacker exploited a blockchain vulnerability that Juno planned to address via an update scheduled for a few hours after the attack. The developer says the vulnerability had been publicly disclosed, as it impacted all blockchains that use the CosmWasm smart contract platform.

This is the second major challenge Juno has faced in the past month. In March a controversial governance vote removed tokens from a “whale” accused of manipulating a JUNO airdrop – an unprecedented case of a decentralized community directly voting to cut a wallet’s token balance.

The JUNO token, which has a $1 billion market cap according to CoinGecko, has dropped 7% in the past 24 hours.

As of now, the identity of the attacker is unknown.

According to Daniel Hwang, head of protocols at Stakefish, which runs a validator for Juno, members of the Juno community are trying to figure out who would have been motivated to execute the attack for no obvious financial gain. According to Hwang, token holders are pointing fingers at potential culprits ranging from competitor blockchains to bagholders on the losing end of last month’s governance vote.


Read more about

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

CoinDesk - Unknown

Sam is a reporter at CoinDesk focused on decentralized technology, DeFi and DAOs. He owns ETH, BTC and MATIC.

CoinDesk - Unknown

Sam is a reporter at CoinDesk focused on decentralized technology, DeFi and DAOs. He owns ETH, BTC and MATIC.