PT-2026-98192 · Unknown · Ixo-Blockchain

CVE-2026-61604

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ixo Blockchain versions prior to 8.0.0
Description Improper authorization in the x/bonds module allows the movement of funds from an address resolved from a DID verification method without verifying if the address belongs to the transaction signer. Since any account can list an arbitrary blockchainAccountID as a verification method on a DID they control, an attacker can register a victim's address to their own DID to move the victim's balances into an attacker-controlled bond and subsequently withdraw the funds off-chain. This issue was exploited on the ixo mainnet (ixo-5) on 2026-06-20, affecting any account holding tokens usable by a bond without requiring victim keys or signatures. Affected handlers include MsgMakeOutcomePayment(), MsgBuy(), MsgSell(), MsgSwap(), MsgWithdrawShare(), and the batch order processor.
Recommendations Upgrade to version 8.0.0.

Exploit

Fix

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61604
GHSA-W3RP-4CM2-4WGC

Affected Products

Ixo-Blockchain