{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/consensus-flaw/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ixofoundation:ixo-blockchain:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-61604"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ixo-blockchain (\u003c 8.0.0)"],"_cs_severities":["critical"],"_cs_tags":["blockchain","financial-theft","vulnerability","consensus-flaw"],"_cs_type":"advisory","_cs_vendors":["ixoFoundation"],"content_html":"\u003cp\u003eThe ixo-blockchain project identified a critical authorization vulnerability (CVE-2026-61604) affecting the x/bonds module across multiple versions. The flaw resides in the handling of DID (Decentralized Identifier) verification methods. The system incorrectly resolved addresses from these methods without verifying that the resolved address belonged to the transaction signer.\u003c/p\u003e\n\u003cp\u003eBecause any account can register an arbitrary blockchainAccountID as a verification method on a DID they control, attackers were able to associate victim addresses with their own DIDs. By executing bond-related transactions such as MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, or MsgWithdrawShare, the attacker forced the chain to drain funds from the victim's account into a bond controlled by the attacker. This vulnerability was exploited on the ixo-5 mainnet on 2026-06-20. The issue is deeply embedded in the chain's state-machine logic, necessitating a consensus-level upgrade to v8.0.0, which disables the x/bonds module entirely to stop unauthorized fund movements.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates or controls a Decentralized Identifier (DID) on the ixo network.\u003c/li\u003e\n\u003cli\u003eAttacker registers an arbitrary victim's blockchain address as a verification method within the DID document.\u003c/li\u003e\n\u003cli\u003eThe system fails to validate authorization, incorrectly mapping the victim's account to the attacker-controlled DID.\u003c/li\u003e\n\u003cli\u003eAttacker submits a bond-related transaction (e.g., MsgBuy or MsgSwap) specifying the compromised DID.\u003c/li\u003e\n\u003cli\u003eThe x/bonds module, failing to verify signer ownership, pulls assets from the victim's address based on the tainted DID resolution.\u003c/li\u003e\n\u003cli\u003eThe transaction completes, transferring the victim's tokens into an attacker-controlled bond.\u003c/li\u003e\n\u003cli\u003eAttacker proceeds to withdraw and bridge the accumulated proceeds off-chain.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability led to the unauthorized drainage of funds from arbitrary user accounts on the ixo-5 mainnet. Because the attack required no victim keys or system access, any account holding a balance in a token compatible with the x/bonds module was at risk. The total financial impact highlights the severity of consensus-level authorization flaws in blockchain state machines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all ixo-blockchain node and validator software to version 8.0.0 immediately.\u003c/li\u003e\n\u003cli\u003eNote that v8.0.0 disables the x/bonds module; operators should plan for the functional loss of this module until a future, secured version is released.\u003c/li\u003e\n\u003cli\u003eAudit recent on-chain activity related to DID document updates and subsequent x/bonds transactions (MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, MsgWithdrawShare) to identify potential account drainage events during the window of exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-24T20:04:10Z","date_published":"2026-09-24T20:04:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ixo-bonds-drain/","summary":"A critical authorization flaw in the ixo-blockchain consensus logic allows unauthorized movement of user funds via DID-linked address manipulation.","title":"Critical Authorization Bypass in ixo-blockchain x/bonds Module","url":"https://feed.craftedsignal.io/briefs/2026-09-ixo-bonds-drain/"}],"language":"en","title":"CraftedSignal Threat Feed - Consensus-Flaw","version":"https://jsonfeed.org/version/1.1"}