Crypto
Home›Crypto›Market Structure›Zero-balance bug exposed Provenance markers to possibl…
Zero-balance bug exposed Provenance markers to possible takeover
Trail of Bits said the flaw could also enable unauthorized minting and withdrawals from escrow tied to roughly 30 quadrillion nhash, worth about $500,000 when discovered.
Trail of Bits disclosed a security flaw in the Provenance Blockchain authorization system that it said could expose 82 live mainnet asset accounts to takeover. The firm warned that successful abuse could let an attacker mint an affected token and withdraw assets held in escrow by using admin and withdrawal permissions gained through a second transaction.
The issue involves Provenance markers, special asset accounts that govern a token's supply, permissions, and escrow balance. Trail of Bits said the authorization check relied on a stale supply field, where non fixed markers could show zero in the marker supply even while the bank module tracked nonzero circulating supply, causing a balance check to incorrectly approve permission changes for accounts with no marker tokens.
Trail of Bits said the affected nhash escrow totaled roughly 30 quadrillion nhash, worth about $500,000 at HASH prices when the issue was discovered. It estimated that three Provenance Blockchain Foundation programs held most of the amount, including grant0051 with about 19.23 quadrillion nhash, provenance.validator.incentive.program with about 8.56 quadrillion, and grant0077 with about 2.49 quadrillion.
The security firm said it found the flaw in March and reported it to Provenance on April 1. Trail of Bits said fixes were released in v1.28.0 on May 1, including a zero supply guard that blocked the reported path across all 82 identified markers, with a follow-on change to read live supply included in v1.29.0 on June 8.