Trail of Bits disclosed an authorization flaw in Provenance Blockchain that exposed 82 live mainnet marker accounts to potential takeover. An attacker holding none of a marker's tokens could exploit a zero-versus-zero supply check to obtain administrative, minting and withdrawal permissions, potentially minting unrestricted tokens or withdrawing escrowed assets. The affected markers held about 30 quadrillion nhash, worth roughly $500,000 at HASH prices when the flaw was discovered. A 74-marker subset faced unauthorized minting risks across stablecoins, wrapped assets, consortium deposits, tokenized mortgage participations and yield tokens. Provenance released fixes in v1.28.0 on May 1 and v1.29.0 on June 8; the disclosure did not report whether unauthorized access, minting or withdrawals occurred.