OAuth consent-scope forgery allows any customer account to obtain administrative scopes (Galoy/Blink stack)
October 6, 2026
An authorization flaw in the Galoy/Blink OAuth consent application allowed an ordinary customer to obtain scopes the OAuth client had not requested. In affected deployments, the administrative gateway accepted these tokens and the admin API trusted their scopes, enabling customer-data access and account takeover through contact-detail changes. The primary source fix is included in version 0.22.65; operators must update the consent and API components and configure the admin gateway correctly.
Three chained defects allowed any registered customer account of an affected deployment to obtain full administrative
OAuth scopes:
apps/consent) accepted the grant_scope list from the browser's form submissionoauth2_introspection path configured for service clientsrequired_scope, no target_audience, no trusted_issuers and no client restriction.scope string as the entire authorization decision (no subjectThe attack requires no signing-key compromise or cryptographic token modification: the identity provider issues the
over-scoped tokens, so standard token-signature validation does not detect the attack.
GaloyMoney/blink contains the vulnerable consent code from commit59150be0e049a28d432c9c3200f4f649bfbf8b83 (PR #3339,6c536737a327013f2ebe0a37091a3277ec802373.c46a6939ee102f391d65a55133f9f1b99b4dc849 (2023-10-01), andbe54143fcf6fc395b34359c3d85072c5bed8e943 (2023-10-09).blinkbitcoin/blink inherited this code. Source revisions containing the introducing commit and lacking the fix0.22.64 predates the fix. The primary source correction is4d9a4b1fbb0537b31a48a0c05ea42222ae26892d, included in tag 0.22.65.0.22.65 or a later revision retaining the fix, orADMIN_API_JWT_AUDIENCE set to galoy-admin or an equivalent dedicated value shared with the trusted adminThe contact-change freeze in #861 is additional containment, not a correction
of scope issuance. Its configuration can disable the freeze, and it does not prevent administrative data reads.
Operators of derived deployments can request a short vulnerable/patched check procedure at bounty@blinkbtc.com; we share
it once we have confirmed that the requester operates a deployment.
Source-level evidence is available in the public repository:
grant_scope values are read from the form and passed to Hydra's acceptOAuth2ConsentRequest without checking that they are a subset of requested_scope:invalid_scope, and adds dedicated audience validation to the admin API:For an isolated deployment with the affected gateway configuration, the vulnerable behavior is issuance of an OAuth token carrying consent-submitted scopes beyond those originally requested by the client, followed by acceptance of that authority by the admin API. With the corrected consent handler, the same out-of-request grant must be rejected with invalid_scope. Independently, the corrected admin API must reject JWTs without its configured admin audience, and the gateway must reject customer access to administrative paths.
The complete vulnerable/patched reproduction procedure is shared with maintainers and verified deployment operators through bounty@blinkbtc.com. This public evidence describes the source defect and expected validation outcomes; it does not include the operator-only execution runbook.
This is an incorrect-authorization vulnerability (CWE-863) that permits escalation from an ordinary customer account to administrative privileges. It affects operators and customers of deployments running the vulnerable consent code with the permissive administrative authorization path described in Details. No existing administrator credentials or interaction by another user are required.
Impact on affected deployments: complete administrative API access, including read access to customer account data (balances,
transaction history, contact details, auth methods), mutation of customer contact details (enabling account takeover via
passwordless login), account-level changes (withdrawal-limit raises) and other administrative operations. Money movement
additionally depends on each deployment's payment rails. In the September 2026 Blink incident this chain enabled the
takeover of 35 custodial accounts and the drain of 24 (about 6.61 BTC net proceeds to the attacker).
See the post-mortem linked in References.
October 6, 2026