CVE-2026-61604 is an improper authorization vulnerability in ixo Blockchain versions prior to 8.0.0. The x/bonds module resolved a payer or source address from a DID verification method but did not verify that the resolved address was controlled by the transaction signer. An attacker could associate an arbitrary blockchain account address with a DID under the attacker’s control without the address owner’s consent, then invoke affected bond operations to move the victim’s funds into an attacker-controlled bond. Affected operations include MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, MsgWithdrawShare, and batch order processing. The flaw was exploited on ixo mainnet on 2026-06-20.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper-authorization vulnerability in ixo Blockchain's x/bonds and x/entity ICA logic. An attacker could attach a victim-controlled blockchain address as a verification method to an attacker-controlled DID, then cause affected bonds handlers to move the victim's token balance into an attacker-controlled bond without victim keys or signatures.
A consensus/state-machine authorization flaw in the ixo Blockchain x/bonds module. An attacker could add a victim's blockchain address as a verification method on an attacker-controlled DID, then invoke affected bonds operations to move the victim's eligible token balance into an attacker-controlled bond and withdraw or bridge the proceeds.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.