{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nimiq-blockchain-1.5.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["nimiq-blockchain (1.5.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Nimiq"],"content_html":"\u003cp\u003eThe Nimiq blockchain, specifically the \u003ccode\u003enimiq-blockchain\u003c/code\u003e crate (version 1.5.0 and earlier), is susceptible to a transaction replay vulnerability (CVE-2026-46369) due to an off-by-one error in its validity store logic. The software incorrectly evaluates whether a transaction is within the validity window by using strict inequality, which contradicts the protocol's \u003ccode\u003eTransaction::is_valid_at\u003c/code\u003e definition. By crafting a specific \u003ccode\u003evalidity_start_height\u003c/code\u003e, an attacker can bypass the intended replay protection mechanisms for a duration of approximately 10 minutes (59 blocks on MainNet). This mismatch allows an attacker to submit the same signed transaction multiple times, resulting in a double-spend where the sender is debited and the recipient is credited more than once. This issue represents a significant integrity risk to the ledger state and funds.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to double-spending, where the attacker is able to execute a single transaction multiple times. This results in the erroneous debiting of sender accounts and unauthorized crediting of recipient accounts, undermining the integrity of the blockchain ledger and causing financial loss to users. The vulnerability affects all deployments running version 1.5.0 or older of the \u003ccode\u003enimiq-blockchain\u003c/code\u003e Rust implementation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the \u003ccode\u003enimiq-blockchain\u003c/code\u003e crate to the version provided in the vendor patch (pull request 3772) immediately to remediate the validity check logic error. As no effective workarounds exist for this protocol-level flaw, nodes should prioritize upgrading to ensure compliance with the correct transaction validity window implementation.\u003c/p\u003e\n","date_modified":"2026-08-12T16:48:59Z","date_published":"2026-08-12T16:48:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nimiq-blockchain-vulnerability/","summary":"An off-by-one error in the Nimiq blockchain validity store allows for double-spending of transactions by bypassing replay protection within a 10-minute window.","title":"Nimiq Blockchain Transaction Replay Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-nimiq-blockchain-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Nimiq-Blockchain (1.5.0)","version":"https://jsonfeed.org/version/1.1"}