Executive brief
Anchor is a popular framework used to build secure smart contracts on the Solana blockchain. A vulnerability in the InterfaceAccount component allows an attacker to substitute a legitimate account with an unexpected one, potentially bypassing security checks. This could allow unauthorized parties to manipulate contract data or perform actions they are not permitted to do, impacting the integrity of the decentralized application.
Technical details
A vulnerability exists in the `InterfaceAccount` type within the Anchor framework for Solana. The issue was introduced when discriminator checking— a mechanism used to verify that an account is of the expected type—was disabled for this specific component. An attacker can exploit this by passing an unexpected account type where an `InterfaceAccount` is required, leading to improper input validation (CWE-20). This allows for account substitution attacks that can compromise the integrity of smart contract state. The issue is fixed in version 1.0.0-rc.2 by re-enabling or correcting the validation logic.
Affected products
- solana-foundation anchor-lang 1.0.0-rc.1
Timeline
- 2026-05-08: disclosed: Vulnerability reported and fixed in pull request 4139
- 2026-05-13: advisory: GitHub Advisory GHSA-429q-fhh4-r6hj published