{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/babbage/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-56744"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@bsv/wallet-toolbox (\u003c 2.4.0)","@bsv/wallet-toolbox-client (\u003c 2.4.0)","@bsv/wallet-toolbox-mobile (\u003c 2.4.0)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","integrity","bsv","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Babbage"],"content_html":"\u003cp\u003eA critical integrity vulnerability (CVE-2026-56744) exists in the \u003ccode\u003e@bsv/wallet-toolbox\u003c/code\u003e, \u003ccode\u003e@bsv/wallet-toolbox-client\u003c/code\u003e, and \u003ccode\u003e@bsv/wallet-toolbox-mobile\u003c/code\u003e packages. The flaw stems from an insufficient validation process during transaction construction within the \u003ccode\u003ecreateAction\u003c/code\u003e workflow. When using a remote \u003ccode\u003eStorageClient\u003c/code\u003e, the wallet fetches transaction outputs from the storage server; however, the \u003ccode\u003ebuildSignableTransaction\u003c/code\u003e method fails to compare the returned \u003ccode\u003elockingScript\u003c/code\u003e against the outputs originally requested by the application. Consequently, a malicious storage provider can substitute the intended recipient's script with one under their control. The wallet signs this modified transaction, and the UI provides no indication of the swap. This vulnerability impacts all versions of these packages between 1.x and 2.3.x. The attack is specific to the storage operator or entities with access to the storage infrastructure, as the storage server's identity is verified via mutual authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes or compromises a remote storage server used by the target wallet client.\u003c/li\u003e\n\u003cli\u003eVictim initiates a payment request within the wallet application specifying a legitimate recipient.\u003c/li\u003e\n\u003cli\u003eThe wallet client sends a request to the storage server to build the transaction.\u003c/li\u003e\n\u003cli\u003eThe malicious storage server intercepts the request and generates a transaction response containing an attacker-controlled \u003ccode\u003elockingScript\u003c/code\u003e instead of the one requested by the caller.\u003c/li\u003e\n\u003cli\u003eThe wallet client's \u003ccode\u003ebuildSignableTransaction\u003c/code\u003e function retrieves the attacker-provided \u003ccode\u003elockingScript\u003c/code\u003e from the storage response.\u003c/li\u003e\n\u003cli\u003eThe client fails to perform a validation check against the original requested outputs and proceeds to sign the modified transaction.\u003c/li\u003e\n\u003cli\u003eThe wallet broadcasts the signed transaction, transferring funds to the attacker-controlled address while maintaining the original intended address in the UI.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized transfer of funds to attacker-controlled addresses. Because the wallet UI continues to display the original intended recipient, the fraud remains hidden from the victim during and after the transaction process. The vulnerability affects all users relying on remote storage configurations, particularly those using the default \u003ccode\u003estorage.babbage.systems\u003c/code\u003e infrastructure if the operator is compromised or malicious.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of \u003ccode\u003e@bsv/wallet-toolbox\u003c/code\u003e, \u003ccode\u003e@bsv/wallet-toolbox-client\u003c/code\u003e, and \u003ccode\u003e@bsv/wallet-toolbox-mobile\u003c/code\u003e to version 2.4.0 or higher immediately to address CVE-2026-56744.\u003c/li\u003e\n\u003cli\u003eReview application logs for any unexpected changes in destination addresses returned by the storage provider if historical incident investigation is required.\u003c/li\u003e\n\u003cli\u003eImplement strict validation checks in client-side transaction signing logic to ensure that signed outputs strictly match the application-requested outputs before signing.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-24T20:05:29Z","date_published":"2026-09-24T20:05:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bsv-wallet-toolbox-vulnerability/","summary":"A vulnerability (CVE-2026-56744) in @bsv/wallet-toolbox and related packages allows a compromised or malicious storage provider to silently substitute transaction recipient scripts, causing funds to be sent to attacker-controlled addresses.","title":"Transaction Recipient Substitution Vulnerability in @bsv/wallet-toolbox","url":"https://feed.craftedsignal.io/briefs/2026-09-bsv-wallet-toolbox-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Babbage","version":"https://jsonfeed.org/version/1.1"}