Impact
The vulnerability is in the vtoken-minting and slpx pallets of Bifrost, where a signed account may provide any registered channel_id when minting tokens without the system checking that the caller is authorized to mint on that channel. This allows an attacker to inflate the mint volume reported for a chosen channel, causing the protocol’s commission settlement to over‑reward that channel and divert protocol revenue.
Affected Systems
The affected product is Bifrost from Bitfrost.io. The issue applies to all Bifrost releases that include the vtoken‑minting and slpx pallets without the required authorization checks, and no specific version range is provided.
Risk and Exploitability
The risk is that any malicious or compromised signed account that knows a valid channel_id can create arbitrarily high mint volumes for any channel. Although no EPSS score or KEV listing is available and no public exploits are reported, the potential financial loss from misallocated commissions is significant. The attack requires possession of a valid signed account and knowledge of an existing channel_id, conditions that could arise from an insider or a compromised account.
OpenCVE Enrichment