RIADeFi

Axelar publishes CometBFT security-patch release v1.3.8

The Ledger · · Ketju Research

ConfirmedDeveloping evidence

Developing. Some claims here are not yet confirmed; they are listed apart from the confirmed facts. A new version replaces this one when the primary evidence changes.

Affects: Axelar (protocol)

What happened

Axelar published axelar-core v1.3.8 with an upgraded CometBFT dependency containing the fix for CSA-2026-001.

What changed

A patched official validator build became available, creating a concrete infrastructure-version diligence requirement for the watched Axelar dependency.

What did not change

The release says the change is not consensus-breaking and no funds are at risk. It does not prove network-wide validator adoption, an exploit, fund loss, or a gateway-contract change.

Confirmed

  • Axelar Core v1.3.8 was released on 2026-01-23.
  • The release upgrades CometBFT with a fix for CSA-2026-001.
  • Axelar states that the change is not consensus-breaking and that no funds are at risk.

Still open

  • The cached record does not establish validator adoption of v1.3.8 across the live network.
  • The operative vulnerability details and any exposure before upgrade are not stated in the candidate record.

What it means for an advisor

  • Review the Axelar memo's infrastructure-security record and verify that relevant service providers or integrations track the patched validator version.
  • Do not infer that release publication alone proves the live validator set has upgraded.

Sources

  1. Axelar Core v1.3.8 · Axelar ·

Version 1, published . Educational research, not investment advice.