Axelar validators apply a security patch addressing node-crash risk
The Ledger · · Ketju Research
Affects: Axelar (protocol)
What happened
Axelar published core release v1.3.5 with an important CometBFT security patch and a staking-rewards fix. The release urged node operators to apply it promptly and stated that a majority of validators had already done so.
What changed
A patched Axelar Core version became available, and Axelar reported majority-validator adoption intended to prevent validator nodes from crashing.
What did not change
The release said no funds were at risk and did not report a consensus failure, cross-chain message failure, asset loss, or completed adoption by every validator.
Confirmed
- Axelar Core v1.3.5 was released on 2025-12-15.
- The official release identifies an important CometBFT security patch and a staking-rewards fix.
- Axelar stated that the patch prevents node crashes and that a majority of validators had applied it.
- The release stated that no funds were at risk.
Still open
- The release does not identify the vulnerability or affected CometBFT behavior in enough detail to independently assess exploitability.
- The proportion and identity of validators still running unpatched software were not disclosed.
- No primary evidence in the candidate establishes whether the vulnerability caused downtime before patching.
What it means for an advisor
- Add the patch and reported adoption to Axelar's operational-resilience history.
- Review whether any approved integration depended on Axelar during a period when a material validator share remained unpatched.
- Do not interpret majority adoption or the no-funds-at-risk statement as proof that every integration or validator was unaffected.
Sources
- Axelar Core v1.3.5 · Axelar ·
Version 1, published . Educational research, not investment advice.