# SDK security considerations

**URL:** <https://forum.cosmos.network/t/sdk-security-considerations/2747>\
**Category:** Security\
**Created:** [September 25, 2019, 4:12pm UTC](https://forum.cosmos.network/t/sdk-security-considerations/2747 "2019-09-25T16:12:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![maurelian](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/maurelian/32/844_2.png) [@maurelian](https://forum.cosmos.network/u/maurelian)\
**Post date:** [September 25, 2019, 4:12pm UTC](https://forum.cosmos.network/t/sdk-security-considerations/2747/1 "2019-09-25T16:12:47Z")

</div>

Great [call today](https://forum.cosmos.network/t/cosmos-community-security-office-hours/2615)! I didn’t ask this because it felt less relevant to the participants (mostly Cosmos validators) but I’m particularly interested in the security considerations for implementing a sidechain (appchain?) using the Cosmos SDK.

Questions like:

- what known attacks exist at the app layer?
- what common issues and gotchas should be avoided?
- what are the recommended best practices for secure development?
- what are best practices for upgrading a sidechain?

---

<div class="post-metadata">

**Author:** ![Jessysaurusrex](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/jessysaurusrex/32/5057_2.png) [@Jessysaurusrex](https://forum.cosmos.network/u/Jessysaurusrex)\
**Post date:** [October 1, 2019, 5:21am UTC](https://forum.cosmos.network/t/sdk-security-considerations/2747/2 "2019-10-01T05:21:13Z")

</div>

Going to surface these questions in our next internal security call and make sure you get some good answers here! Thanks for joining us, and apologies for the delay here-- we were on a team retreat.
