Loading market data...

Provenance Blockchain flaw let zero-token users take 82 live accounts

Provenance Blockchain flaw let zero-token users take 82 live accounts

Trail of Bits has disclosed a Provenance Blockchain authorization flaw that exposed 82 live mainnet asset accounts to takeover. An attacker holding zero tokens could take admin, mint, and withdrawal permissions on affected markers. Patches shipped in May and June, but the disclosure doesn't say whether anyone actually exploited it.

The zero-supply mismatch

The bug was a mismatch between the bank module's live circulating supply and a marker's supply field, which could sit at zero. An attacker with no tokens could claim a marker whose stored supply read zero while real assets were parked in escrow or circulating on the chain.

What was exposed

All 82 affected markers had zero stored supply but real circulating supply or escrow assets. The escrow held about 30 quadrillion nhash, worth roughly $500,000 when the flaw was found. Three Provenance Blockchain Foundation programs accounted for most of that: grant0051 with around 19.23 quadrillion nhash, the provenance.validator.incentive.program with 8.56 quadrillion, and grant0077 with 2.49 quadrillion.

A subset of 74 markers faced unauthorized minting risk, including bridged stablecoins, wrapped assets, consortium deposits, tokenized mortgage participations, and yield tokens. That's a broad range of live assets, not just a niche corner of the chain.

How the fix landed

Trail of Bits found the issue in March and reported it to Provenance on April 1. A zero-supply guard shipped with v1.28.0 on May 1, blocking the reported path for all 82 markers. A second change in v1.29.0 on June 8 made the authorization check read live supply from the bank module.

The two-step patch closed the specific hole Trail of Bits had flagged and then addressed the root cause. The timeline looks orderly on paper, but the gap between discovery and the first fix ran about a month.

Open questions

The disclosure doesn't mention whether unauthorized access, minting, or withdrawals actually happened. That's the question hanging over this episode now. Neither Trail of Bits nor Provenance has said anything publicly beyond what the report itself states.