CVE-2026-86840
nicheAuthorization flaw in Bifrost vtoken-minting and slpx pallets skews channel commissions
Bifrost's vtoken-minting and slpx pallets contain a missing-authorization flaw (CWE-862/CWE-639): a signed account can supply any registered channel_id when minting without the runtime verifying that the caller is authorized to mint on behalf of that channel. The flaw is triggered by simply submitting a mint transaction referencing an arbitrary registered channel the attacker does not control. By doing so, an attacker can inflate that channel's recorded mint volume, causing protocol commission settlement to disproportionately route commission payments to the attacker-chosen channel. Affected parties are the Bifrost protocol (a Polkadot parachain), its registered minting channels/integrators, and anyone entitled to commission distributions; end-user tokens are not described as directly at risk in the available data. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.1% chance of exploitation within 30 days.
What to do: Apply Bifrost's patched runtime upgrade incorporating corrected vtoken-minting and slpx pallets as soon as the fix release is published (no fixed version numbers were included in this advisory data). Operators of registered channels should review their recorded mint volume for unexplained inflation and audit the next commission settlement for skewed distributions. End users of vToken minting or SLPx cross-chain staking need no direct action but should monitor official Bifrost communications for the patch and any settlement corrections.
| Bifrost Finance (Bifrost protocol) Bifrost vtoken-minting and slpx pallets (Substrate runtime pallets) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
- Weakness
- CWE-639, CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.