Nimiq Blockchain Timestamp Validation Vulnerability Allows Future Timestamp Manipulation

Vulnerability

A vulnerability exists in the Nimiq blockchain library for Rust, specifically in versions through 1.3.0. The issue arises from the block timestamp validation, which lacks an upper bound check against the wall clock. While the validation ensures that non-skip blocks have timestamps greater than or equal to the parent's timestamp, and that skip blocks' timestamps equal the parent's timestamp plus a specified timeout, it fails to restrict timestamps from being set arbitrarily far into the future. This flaw can be exploited by a malicious block-producing validator, leading to inflated reward calculations that disrupt the intended monetary supply schedule.

Impact

Exploitation of this vulnerability allows for manipulation of block timestamps, which in turn skews reward calculations and inflates the monetary supply beyond the intended emission schedule.

Added: Apr 10, 2026, 1:27 AM
Updated: Apr 10, 2026, 1:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.