Trail of Bits disclosed a Provenance Blockchain authorization flaw that it said exposed 82 live mainnet asset accounts to takeover. A successful abuse could let someone mint an affected token or withdraw assets held in escrow.
Those special asset accounts, called markers, govern a token’s supply, permissions, and escrow balance. The security firm said the flaw allowed a user who held none of a marker’s tokens to take its admin, mint, and withdrawal permissions, then act on them in a second transaction.
The bug came from a mismatch between two records of token supply. For non-fixed markers, Provenance’s bank module tracks live circulating supply, while the marker’s supply field can remain at zero.
The authorization check read the stale marker field when testing whether an account held the entire supply. Because a new account’s balance was also zero, the check treated zero as equal to zero and approved the permission change.
Trail of Bits said all 82 affected markers had zero stored supply while carrying real circulating supply or assets in escrow.
The disclosed affected nhash escrow totaled roughly 30 quadrillion nhash, worth about $500,000 at HASH prices when the issue was discovered. Three Provenance Blockchain Foundation programs held most of it: grant0051 held about 19.23 quadrillion nhash, provenance.validator.incentive.program held about 8.56 quadrillion, and grant0077 held about 2.49 quadrillion.
A distinct 74-marker token subset, included within the total of 82, faced unauthorized minting risk. It spanned bridged stablecoins and wrapped assets, consortium deposits, tokenized mortgage participations, and yield tokens.
Named examples included uusd.trading, uusdc.figure.se, nbtc.figure.se, cusd.deposit, cguaranteedrateomni, chomebridgeomni, nuva.ylds, and uylds.fcc.
Trail of Bits described a direct inflation risk for unrestricted coin-type markers. Restricted tokens with identity requirements faced supply-integrity and solvency risks even if an attacker could not freely transfer newly created units.

Trail of Bits said it discovered the flaw in March and reported it to Provenance on April 1. It said a zero-supply guard released with v1.28.0 on May 1 blocked the reported path against all 82 identified markers.
A second change made the authorization check read live supply from the bank module, and the project included it in v1.29.0 on June 8.
GitHub records show the code changes were merged and released. The Trail of Bits disclosure does not say whether chain analysis found unauthorized access, minting, or withdrawals, or whether it notified affected issuers and users.
Source link
Author

- Ytv Market News
- Share-market news writer and analyst with deep experience covering equities, commodities, forex, and cryptocurrencies for readers in the USA, UK, Canada, and Australia. Ytv Market News delivers timely market updates, practical trading insights, and clear explanations of macro and company-level catalysts that move prices. Combines on-the-ground financial reporting with technical analysis, using concise charts and actionable ideas to help investors and traders make smarter decisions.
Latest entries
Stock Market VideosAugust 26, 2026A 25-Year-Old’s $45 Billion Fund Just Blew Up
UsaAugust 26, 2026A Leading Hedge Fund Just Placed Massive Bets on Broadcom and Intel Stocks. Should You Follow Suit?
AustraliaAugust 26, 2026Corporate Travel Management secures new funding and updates on FY25 and FY26 earnings
Crypto NewsAugust 26, 2026Bitcoin slips below $78K as longs absorb $270M hit
