PT-2026-98192 · Unknown · Ixo-Blockchain
CVE-2026-61604
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ixo Blockchain versions prior to 8.0.0
Description
Improper authorization in the
x/bonds module allows the movement of funds from an address resolved from a DID verification method without verifying if the address belongs to the transaction signer. Since any account can list an arbitrary blockchainAccountID as a verification method on a DID they control, an attacker can register a victim's address to their own DID to move the victim's balances into an attacker-controlled bond and subsequently withdraw the funds off-chain. This issue was exploited on the ixo mainnet (ixo-5) on 2026-06-20, affecting any account holding tokens usable by a bond without requiring victim keys or signatures. Affected handlers include MsgMakeOutcomePayment(), MsgBuy(), MsgSell(), MsgSwap(), MsgWithdrawShare(), and the batch order processor.Recommendations
Upgrade to version 8.0.0.
Exploit
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ixo-Blockchain