External risk intelligence

MultiversX Multisig Authorization Bypass Allows Fund Draining

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-106511

This vulnerability exists within an on-chain smart contract implementation for a multisig system. Smart contracts operate on the blockchain and are not internet-facing services, web applications, or network gateways. Interaction requires specific blockchain transactions, and the vulnerability is restricted to the internal logic of the smart contract's authorization mechanism.

Missing Authentication

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects an on-chain smart contract system for managing multiple signatures on the MultiversX platform. A flaw in the authorization checks allows a designated proposer to move all funds from a contract without the required approvals, potentially leading to a complete loss of assets. The main concern is confirming relevance and exposure within our specific environment.

  • A contract flaw allows unauthorized single-party fund transfers.
  • This bypasses crucial security controls for asset protection.
  • Confirm this smart contract system is not in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by leveraging the Proposer role within the multisig smart contract system. This role has the ability to initiate transactions, and due to a missing authorization check, can execute actions that should be restricted. If exploited, this could lead to the complete draining of the contract's funds.

  • Requires Proposer role access.
  • Perform barred actions without authorization.
  • Risk of draining all contract funds.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in the on-chain multisig smart contract system could allow an account with the Proposer role to move funds independently, potentially draining all EGLD/ESDT balances from a contract. This could occur when the contract's authorization checks are bypassed, even without any required signatures.

  • Contract funds.
  • Proposer role bypasses checks.
  • All contract funds drained.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects an on-chain multisig smart contract implementation. Ownership typically resides with the application owner or platform team responsible for the smart contract's development and deployment. The first practical step is to identify all instances of this smart contract, assess their criticality, and then coordinate with the accountable owner for remediation.

  • Application owners should manage the issue.
  • Verify contract reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the mx-multisig-and-modules system?

This is a reference implementation of a multisig smart contract system on the MultiversX blockchain. It allows groups to manage shared funds by requiring multiple signatures for transactions. Developers use this code as a template to build their own on-chain governance or asset management contracts, which handle native EGLD and ESDT tokens.

How does CVE-2026-106511 affect authorization?

This vulnerability involves a missing authorization check, categorized as improper access control and missing authentication. In the context of this CVE, it means the smart contract fails to verify if a user has sufficient permissions for a specific action. Because this check is absent, the system incorrectly trusts any account assigned the Proposer role to act entirely on its own.

Does any account trigger this vulnerability?

No, the vulnerability is not triggered by just any account on the network. It specifically requires an account to hold the Proposer role within the multisig contract. A standard user account without this assigned role cannot exploit the missing authorization check to initiate unauthorized transfers.

Is this vulnerability an internet-facing risk?

No. According to Halo Surface Signal, this is an on-chain smart contract issue, not a traditional internet-facing web service. Because it lives on the blockchain, the risk is tied to the contract's internal logic and state, rather than being reachable through standard network or web exploitation techniques.

How should I respond if I use this contract?

First, locate all deployed smart contracts based on this specific multisig implementation. Once identified, evaluate the importance of the assets those contracts hold. Finally, coordinate with the team that manages the contract deployment to review the current authorization logic and plan necessary updates to enforce required signature approvals.

References