-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0180 ============================================================ Advisory-ID: 0xCERT-2026-0180 Severity: Critical Published: 2026-09-24T18:17:15.707Z Updated: 2026-10-08T22:46:38.406Z Chains: Cosmos Hub URL: https://www.0xcert.com/advisory/0xCERT-2026-0180 Title: CVE-2026-61604: The ixo Blockchain Summary - ------- The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, and MsgWithdrawShare, as well as the batch order processor. Because any account may list an arbitrary blockchainAccountID as a verification method on a DID it controls (without the consent of that address's owner), an attacker could registe… Details - ------- Summary The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, and MsgWithdrawShare, as well as the batch order processor. Because any account may list an arbitrary blockchainAccountID as a verification method on a DID it controls (without the consent of that address's owner), an attacker could register victims' addresses as verification methods on their own DID and then move the victims' balances into a bond the attacker controlled — later withdrawing and bridging the proceeds off-chain. This was exploited on ixo mainnet (ixo-5) on 2026-06-20. The attack required no victim keys, signatures, or system compromise — any account holding a balance in a token a bond could use was at risk. This was fixed in v8.0.0, delivered via the on-chain v8 software-upgrade. The x/bonds module is disabled: every bonds message is rejected on all routes (top-level, authz, CosmWasm, and ICA), and the bonds batch EndBlocker is a no-op so no further reserve movements can occur. All node operators and validators must upgrade to v8.0.0. The flaw is in chain state-machine logic and can only be remediated by running the patched binary. There is no application-level workaround. The vulnerability is in consensus logic; remediation requires the network to run the patched (v8.0.0) binary. The bonds module remains disabled in v8.0.0 and will only be re-enabled in a future release once the signer-authorization model has been corrected. Severity Critical (CVSS 9.3), as scored by NVD. Weakness - - CWE-285 - - CWE-862 Recommended actions - - Check whether you run or depend on the affected component and version - - Apply the vendor's fix or mitigation from the references below Source & attribution This 0xCERT advisory summarises CVE-2026-61604 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-61604. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://nvd.nist.gov/vuln/detail/CVE-2026-61604 - - https://github.com/ixofoundation/ixo-blockchain/security/advisories/GHSA-w3rp-4cm2-4wgc Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRloJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmfg/pMCWTZgrZgakedqJIHyS9SbFsn3YbJkYXD+ ymSs4hYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAADWoAEAgPdfummvkTpZhKse knNW93a3LVwXnCFvuvmae8Hm7DMA/20XtzTR9XumNhYtQpS7A/L4GbYOmDom j+DiJTdPpXcL =HTEM -----END PGP SIGNATURE-----