Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability was identified in the ixo Blockchain's x/bonds module, affecting versions prior to 8.0.0. This flaw allowed attackers to misappropriate funds from user balances by exploiting how addresses were verified within the module. While the issue was exploited on the mainnet in June 2026, the fix has been implemented through an on-chain software upgrade to version 8.0.0, which disables the compromised module.
- Funds were stolen by linking victim accounts to attacker-controlled bonds.
- This exploited core blockchain logic, not user-specific credentials.
- Confirm network participants have upgraded to the patched version.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by linking a victim's address to their own decentralized identifier (DID) as a verification method. This would allow the attacker to move funds from the victim's account to a bond they control, and then withdraw and bridge those proceeds off-chain. This attack was exploited on the ixo mainnet, impacting any account holding a balance in a token a bond could use.
- Attacker links victim address to their DID.
- Attacker moves funds to their controlled bond.
- Victims lose balances to attacker's control.
Live Threat
Current exploitation, exposure, and threat context
The ixo Blockchain's x/bonds module could allow an attacker to move victims' token balances into a bond controlled by the attacker. This could occur when an attacker registers a victim's address as a verification method on their own DID, enabling the attacker to move funds without victim keys or consent, as seen in a past mainnet exploitation.
- Victim token balances.
- Attacker registers victim's address as DID verification.
- Funds could be moved to attacker-controlled bond.
Operational Fix
Recommended remediation, mitigation, and detection steps
The ixo Blockchain's core state-machine logic is affected, requiring action from node operators and validators. The initial step is to confirm all nodes are running the patched version to prevent further unauthorized fund movements.
- Node operators and validators own remediation.
- Verify all nodes run patched software.
- Coordinate network-wide upgrade to v8.0.0.