Trail of Bits flags bug risking 82 Provenance assets and $500,000 HASH escrow

Trail of Bits disclosed an authorization flaw in Provenance Blockchain that exposed 82 live mainnet marker accounts to potential takeover. An attacker holding none of a marker's tokens could exploit a zero-versus-zero supply check to obtain administrative, minting and withdrawal permissions, potentially minting unrestricted tokens or withdrawing escrowed assets. The affected markers held about 30 quadrillion nhash, worth roughly $500,000 at HASH prices when the flaw was discovered. A 74-marker subset faced unauthorized minting risks across stablecoins, wrapped assets, consortium deposits, tokenized mortgage participations and yield tokens. Provenance released fixes in v1.28.0 on May 1 and v1.29.0 on June 8; the disclosure did not report whether unauthorized access, minting or withdrawals occurred.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.