Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability affects an on-chain smart contract system for managing multiple signatures on the MultiversX platform. A flaw in the authorization checks allows a designated proposer to move all funds from a contract without the required approvals, potentially leading to a complete loss of assets. The main concern is confirming relevance and exposure within our specific environment.
- A contract flaw allows unauthorized single-party fund transfers.
- This bypasses crucial security controls for asset protection.
- Confirm this smart contract system is not in use.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by leveraging the Proposer role within the multisig smart contract system. This role has the ability to initiate transactions, and due to a missing authorization check, can execute actions that should be restricted. If exploited, this could lead to the complete draining of the contract's funds.
- Requires Proposer role access.
- Perform barred actions without authorization.
- Risk of draining all contract funds.
Live Threat
Current exploitation, exposure, and threat context
A vulnerability in the on-chain multisig smart contract system could allow an account with the Proposer role to move funds independently, potentially draining all EGLD/ESDT balances from a contract. This could occur when the contract's authorization checks are bypassed, even without any required signatures.
- Contract funds.
- Proposer role bypasses checks.
- All contract funds drained.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects an on-chain multisig smart contract implementation. Ownership typically resides with the application owner or platform team responsible for the smart contract's development and deployment. The first practical step is to identify all instances of this smart contract, assess their criticality, and then coordinate with the accountable owner for remediation.
- Application owners should manage the issue.
- Verify contract reachability and criticality.
- Plan remediation based on assessed risk.