# Censure Allnodes for insecure VaaS practices

**URL:** <https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519>\
**Category:** Signaling/Text\
**Created:** [January 29, 2023, 6:06am UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519 "2023-01-29T06:06:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jacobgadikian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jacobgadikian/32/6994_2.png) [@jacobgadikian](https://forum.cosmos.network/u/jacobgadikian)\
**Post date:** [January 29, 2023, 6:06am UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/1 "2023-01-29T06:06:16Z")

</div>

In recent days it has come to our attention that [allnodes.com](http://allnodes.com) has informed customers of its VaaS service that:

- It is possible for [allnodes.com](http://allnodes.com) to hold validator seed phrases, while claiming to operate in a non custodial manner.
- Deleting these seed phrases on [allnodes.com](http://allnodes.com) after [allnodes.com](http://allnodes.com) has sent them to their customers via a web based DM means that the seed phrases are no longer compromised.

Here is a document on the depths of compromise on Luna classic:

> **[Allnodes](https://docs.google.com/document/d/1AIOOrHiNAFQKwzaeDNyJJJx8SwXNlaSUcZbasnezXS4/edit?usp=drivesdk)**
>
> Allnodes compromises 100% of their clients on most pos networks therefore there are messes on 67 chains This document originally focused on Luna classic. There is a list of affected chains below. It's everywhere. This document is being updated in...

In cryptocurrency, custodial services hold cryptographic secrets. Non custodial services do not. Allnodes is distributing false information to cosmos, as illustrated by the following screenshots:

![|185.0x361.0](https://lh3.googleusercontent.com/Y2fXgr8RjXFjGjHfMUy8W3QxKa8PxDk5indOBxvQF78QE4Lx2XhmoTLFcGOZIdh-M75Z8Qg3_eiKTBi3wTDbx5c-8Id6MBtOaacGRQrJq_rrF7XuVuYlk_iAo-nAdkcZQTvMXtuNaz7dv2AYjABMw9H3CNThmeaUzk9ZU6zSelsjzYR0KCP-cABAsVv2jA)

![|247.0x434.0](https://lh5.googleusercontent.com/k6X1mdxAMtwm8USdn-CunzKT1XcYuvIOxhdiQ0XuNG04VWkE1L2jiSWpJ6r3A2ppA3ulsK3Ehx7nGQ7zR1S59193oPePTEiGUhtQkOVkMhdkzV776qH53cyifX6pRkkQtHFXIEKbeRS_9GkSRpcP0Q7zep1nsZJEL03U9N3hZqMfXu4c2erohzfVu69nPg)

![|202.0x165.0](https://lh3.googleusercontent.com/TOkwhgB0lJ-SDOl0-3lsHS5ajOtxFCeydBWuUShP2tx2ddcjvtmBTqa1YU32TUv9nDi0h3ew9nOZS4kCQdajjJrHjSSHhMDh9bLQxxLdQf4_Igqr_XGsRJTrROJ23-PfzEp5PoAhd5Dv_4ijuhPrmfrE_EgUhN_BgO5RYz0EXksYb00fEMlstNOqd0MMRQ)

![|247.0x364.0](https://lh3.googleusercontent.com/IvDm6R1KQQssMaT3426CPOOdIAWyGlBUl4ZazMTmBfNOxBQPB8N7ScSKwxF5gU95vBosWzRlruVoSzMKeSMC_6wKRuWFrStVm2o6xDJNdHckRH0ATU2bJlusctjFqHTbCqY30J6avc9xfSB0BYOhB-yjPxIqMCe5YqLZvlPDuGUHDBm8iFPR_g-Z_q9xHg)

![|247.0x231.0](https://lh5.googleusercontent.com/w8FyLGP0bvSFkii9kzrEP3TsQfpn9spEy-LGbvYnBI8WY85UP-IgrheRlba80dD6wn5SKHLR2JZh9Qfb64DNGoi6LxJbqna6LL0bLhp7GSYNKK4ubdmdHAUb3uqCsSBs3-G4aT02hwk_I6fWyt16cUlnzfhTdES9gry1nzdNenlj51oN1XNbAudJSBMCLw)

Vote YES to censure [allnodes.com](http://allnodes.com) for irresponsible key management on behalf of its VaaS clients, thereby endangering the cosmos hub.

Vote NO to affirm [allnodes.com](http://allnodes.com) claims

Vote ABSTAIN to express no opinion

Vote NoWithVeto to contribute to a veto tally. If that exceeds 1/3rd of the

---

<div class="post-metadata">

**Author:** ![Jcook\_14](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jcook_14/32/7666_2.png) [@Jcook\_14](https://forum.cosmos.network/u/Jcook_14)\
**Post date:** [January 29, 2023, 7:20pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/2 "2023-01-29T19:20:20Z")

</div>

I feel like we need to figure out a way to make this practice in general, a censorable offense. Or figure a new way to educate delegators to be aware of this practice, and disincentivize it through community efforts. It’s somewhat of a SRAAS (Systemic Risk as a Service).

Not sure really what the best way to approach this situation is, even without the misappropriation of keys by All Nodes, this practice is a serious centralization threat. It’s essentially pooling validators, and with Interchain Security making validating ever more challenging, we need to find a way to nip this practice in the bud fast.

---

<div class="post-metadata">

**Author:** ![jacobgadikian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jacobgadikian/32/6994_2.png) [@jacobgadikian](https://forum.cosmos.network/u/jacobgadikian)\
**Post date:** [January 30, 2023, 8:28pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/3 "2023-01-30T20:28:52Z")

</div>

Strongly agreed.

One way to do ics is with exactly the kind of orchestration systems that allnodes likely uses.

Also, found another.

---

<div class="post-metadata">

**Author:** ![lexa](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/lexa/32/7415_2.png) [@lexa](https://forum.cosmos.network/u/lexa)\
**Post date:** [January 31, 2023, 3:26pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/4 "2023-01-31T15:26:31Z")

</div>

‘Censure’ as in expressing formal disapproval? Just want to confirm that this is a signalling prop

---

<div class="post-metadata">

**Author:** ![jacobgadikian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jacobgadikian/32/6994_2.png) [@jacobgadikian](https://forum.cosmos.network/u/jacobgadikian)\
**Post date:** [February 1, 2023, 1:17am UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/5 "2023-02-01T01:17:34Z")

</div>

that’s correct 🙂

expressing formal disapproval, and nothing more.

---

<div class="post-metadata">

**Author:** ![Hydra\_Guy](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/hydra_guy/32/4795_2.png) [@Hydra\_Guy](https://forum.cosmos.network/u/Hydra_Guy)\
**Post date:** [February 27, 2023, 2:07pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/6 "2023-02-27T14:07:52Z")

</div>

What happens if Allnodes is censored on Cosmos blockchain? Is this like being ‘jailed’? And what happens to those who have delegated their ATOM with Allnodes?

---

<div class="post-metadata">

**Author:** ![jacobgadikian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jacobgadikian/32/6994_2.png) [@jacobgadikian](https://forum.cosmos.network/u/jacobgadikian)\
**Post date:** [February 27, 2023, 2:15pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/7 "2023-02-27T14:15:37Z")

</div>

It’s a formal criticism.

- nothing changes for allnodes, except that there’s been a gov prop censuring them. We will not censor them.

- Nothing changes for allnodes delegators, except that they now know that the cosmos hub thinks that they have behaved irresponsibly and should redelegate.

---

<div class="post-metadata">

**Author:** ![jacobgadikian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jacobgadikian/32/6994_2.png) [@jacobgadikian](https://forum.cosmos.network/u/jacobgadikian)\
**Post date:** [February 28, 2023, 12:08pm UTC](https://forum.cosmos.network/t/censure-allnodes-for-insecure-vaas-practices/9519/8 "2023-02-28T12:08:15Z")

</div>

Here’s some brief commentary on the description of security research as hostile by a board member of the ICF’s company:

> <https://twitter.com/gadikian/status/1630527548420661248>
>
> Chorus One @ChorusOne

It should be noted that chorus one also provides validator as a service services on the cosmos hub.

It is my strongly convicted belief that none of the many teams contributing to the research that led to the passage of this proposal acted in a hostile fashion, however it is also my strongly convicted belief that numerous individuals connected to [allnodes.com](http://allnodes.com) did in fact act in a hostile fashion.
