HAQQ v1.9.2 Upgrade
⚠️ Security fix upgrade
This release fixes a vulnerability found in CometBFT. We cannot disclose the code until the vulnerability is published. Publication of the vulnerability has been delayed to allow networks to update.
This release was made possible thanks to a timely and responsible disclosure of the vulnerability by the Cosmos Hub team.
Binary-only release. Apply the new binary as soon as possible.
Do not build this binary from source: the security fix is not included in the tagged commit.
Additional notes
Once 2/3 of validators are updated, the HAQQ chain will be secure.
As always, operators have ultimate authority over the code they choose to run. If you do not trust the binary based on the team that has published it and the accounts who have socially validated it, you do not have to run it. You can wait until we have approval to release the source and build it then. This release and v1.9.1 are compatible except for cases where an attempt is made to exploit the vulnerability that v1.9.2 patches (details of which cannot be safely released yet).