NRDAX-T0409 - Blocked Address Validation Bypass
consensus_abuse · active · first seen 2026-07-19
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
ASA-2024-003 / GHSA-4j93-fm92-rp4m (cosmos-sdk cosmos-sdk <= v0.50.3 / <= v0.47.8): x/auth/vesting MsgCreateVestingAccount / MsgCreatePermanentLockedAccount did not reject a blocked `to_address` (a mo
instances (1)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| cosmos | cosmos_vesting_blocked_address | lab | reverse-engineered-cve | cosmos_vesting_blocked_address | GHSA-4j93-fm92-rp4m ↗ |
related (consensus_abuse)
NRDAX-T0024 - Compact Block FillBlock Duplicate Crash active NRDAX-T0056 - Duplicate Input Validation-Bypass Crash active NRDAX-T0143 - Malformed Field Gossip Before Validation active NRDAX-T0165 - Missing Zero-Guard Divide-By-Zero Halt active NRDAX-T0202 - Peer Timestamp Skew Manipulation active NRDAX-T0207 - Pre-Verify Gossip Flood active NRDAX-T0211 - Premature Processing Index-Out-Of-Range Panic active NRDAX-T0298 - Timestamp Integer Overflow Netsplit active
cite
https://nrdax.com/techniques/NRDAX-T0409
plain
NRDAX Registry. Technique NRDAX-T0409.
bibtex
@misc{nrdax_NRDAX_T0409,
title = {Blocked Address Validation Bypass (NRDAX-T0409)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0409},
} json (csl)
{
"id": "nrdax-NRDAX-T0409",
"type": "dataset",
"title": "Blocked Address Validation Bypass (NRDAX-T0409)",
"URL": "https://nrdax.com/techniques/NRDAX-T0409",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0409-blocked-address-validation-bypass)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0409 nrdax cite NRDAX-T0409 --format bibtex