RIADeFi

Axelar validators apply a security patch addressing node-crash risk

The Ledger · · Ketju Research

ConfirmedConfirmed evidence

Affects: Axelar (protocol)

What happened

Axelar published core release v1.3.5 with an important CometBFT security patch and a staking-rewards fix. The release urged node operators to apply it promptly and stated that a majority of validators had already done so.

What changed

A patched Axelar Core version became available, and Axelar reported majority-validator adoption intended to prevent validator nodes from crashing.

What did not change

The release said no funds were at risk and did not report a consensus failure, cross-chain message failure, asset loss, or completed adoption by every validator.

Confirmed

  • Axelar Core v1.3.5 was released on 2025-12-15.
  • The official release identifies an important CometBFT security patch and a staking-rewards fix.
  • Axelar stated that the patch prevents node crashes and that a majority of validators had applied it.
  • The release stated that no funds were at risk.

Still open

  • The release does not identify the vulnerability or affected CometBFT behavior in enough detail to independently assess exploitability.
  • The proportion and identity of validators still running unpatched software were not disclosed.
  • No primary evidence in the candidate establishes whether the vulnerability caused downtime before patching.

What it means for an advisor

  • Add the patch and reported adoption to Axelar's operational-resilience history.
  • Review whether any approved integration depended on Axelar during a period when a material validator share remained unpatched.
  • Do not interpret majority adoption or the no-funds-at-risk statement as proof that every integration or validator was unaffected.

Sources

  1. Axelar Core v1.3.5 · Axelar ·

Version 1, published . Educational research, not investment advice.