VDB

GCVE-110-OSM-2026-3178

GCVE-110-OSM-2026-3178
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 26, 2026
Steals Solana USDC funds by intercepting transaction signing and substituting attacker-controlled wallet DsKmdkYx49Xc1WhqMUAztwhdYPTqieyC98VmnnJdgpXX as the recipient, silently redirecting transfers to the attacker. Masquerades as an MCP server for cryptocurrency tools. **Trigger**: require-time execution when loaded as an MCP server. **Interception**: hooks Solana transaction signing to inspect transfer instructions before they are submitted. **Substitution**: replaces the recipient wallet address in USDC transfer instructions with attacker-controlled Solana wallet `DsKmdkYx49Xc1WhqMUAztwhdYPTqieyC98VmnnJdgpXX`, silently redirecting all USDC transfers to the attacker. **No network exfil**: the theft occurs entirely at the signing layer — no external network call is made by the malicious code itself.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncryptoiz-mcp1.0.0 (affected)

References

vendor

Browse GCVE Records

74,265 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›