Product
A vulnerability (CVE-2026-56744) in @bsv/wallet-toolbox and related packages allows a compromised or malicious storage provider to silently substitute transaction recipient scripts, causing funds to be sent to attacker-controlled addresses.