New Discord Announcement from THORChain Devs #🚨thornode-mainnet
## CosmWasm security posture — patch incoming
Status on the CosmWasm / `MsgStoreCode` issue and where we stand:
With **ASLR and PIE enabled**, the attack surface for the known vulnerability is covered — exploitation is mitigated at the memory layer on every node that has it applied.
Two trust assumptions hold until the patch lands:
* that **all nodes have applied ASLR** — it's node-level, so any host that hasn't doesn't get the mitigation; and
* the **Rujira team**, who hold access to `MsgStoreCode` (when `HALTWASMGLOBAL` is disabled) — which is where the vulnerability lives.
A **patch goes out shortly** that closes this at the source. We'll confirm here when it ships.
@everyone
Post #1015
485