Junglewise Threat Intelligence

CVE-2026-86840: Bifrost vtoken-minting and slpx pallets authorization bypass

CVE-2026-86840 · Severity: critical · CVSS 9.1 · Published 2026-09-08

Executive brief

Bifrost is a blockchain protocol that offers liquid staking tokens (vTokens) through its minting pallets. A vulnerability allows any signed account to claim arbitrary minting volumes on behalf of any registered channel without authorization. This causes the attacker's tokens to be credited toward a victim channel's commission share, diverting protocol revenue intended for the Bifrost treasury to the attacker or their colluding channel partner.

Technical details

The vulnerability is an improper authorization flaw (CWE-862/863) in the `vtoken-minting` and `slpx` pallets' mint extrinsics and the underlying `record_mint_amount` function in the channel-commission pallet. When a user calls mint with a `channel_id` parameter, the code records the minting volume against that channel without verifying: (1) that the channel_id is actually registered in the Channels storage, or (2) that the caller is authorized to mint on behalf of that channel. An attacker can supply any known registered channel_id to inflate that channel's recorded mint volume, which is then used to calculate the channel's share of protocol commissions during the settlement cycle. This allows revenue diversion from the Bifrost treasury to the attacker or colluding channel operator at no capital risk, since the minting itself is legitimate—only the commission attribution is forged. As of the disclosure date, the vendor had not engaged with the reporter and no patch was available.

Affected products

  • Bifrost vtoken-minting pallet <UNKNOWN>
  • Bifrost slpx pallet <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-05-27: other: Private disclosure to vendor
  • 2026-07-13: other: CERT/CC coordination outreach begun
  • 2026-08-31: other: CERT/CC coordination ended without vendor engagement or patch

References