Impact
The vulnerability is present in the vtoken-minting and slpx pallets of Bifrost, allowing a signed account to provide any registered channel_id when minting tokens without verifying that the caller is authorized to mint on that channel. This permits an attacker to inflate the mint volume recorded for a specific channel, causing the protocol’s commission settlement to over‑reward that channel and divert protocol revenue.
Affected Systems
The affected product is Bifrost from Bitfrost.io. The issue applies to all releases that include the vtoken‑minting and slpx pallets without the required authorization checks, and no specific version range is provided.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, indicating critical severity. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need a legitimate signed account and a known channel_id to inflate mint volumes, which can lead to significant financial loss through commission diversion. Because the flaw lacks host or network‑based checks, the exploitation is limited to insiders or compromised accounts with tokens.
OpenCVE Enrichment