Axelar publishes CometBFT security-patch release v1.3.8
The Ledger · · Ketju Research
Developing. Some claims here are not yet confirmed; they are listed apart from the confirmed facts. A new version replaces this one when the primary evidence changes.
Affects: Axelar (protocol)
What happened
Axelar published axelar-core v1.3.8 with an upgraded CometBFT dependency containing the fix for CSA-2026-001.
What changed
A patched official validator build became available, creating a concrete infrastructure-version diligence requirement for the watched Axelar dependency.
What did not change
The release says the change is not consensus-breaking and no funds are at risk. It does not prove network-wide validator adoption, an exploit, fund loss, or a gateway-contract change.
Confirmed
- Axelar Core v1.3.8 was released on 2026-01-23.
- The release upgrades CometBFT with a fix for CSA-2026-001.
- Axelar states that the change is not consensus-breaking and that no funds are at risk.
Still open
- The cached record does not establish validator adoption of v1.3.8 across the live network.
- The operative vulnerability details and any exposure before upgrade are not stated in the candidate record.
What it means for an advisor
- Review the Axelar memo's infrastructure-security record and verify that relevant service providers or integrations track the patched validator version.
- Do not infer that release publication alone proves the live validator set has upgraded.
Sources
- Axelar Core v1.3.8 · Axelar ·
Version 1, published . Educational research, not investment advice.