Crypto news report · source clearly identified

Zero-balance bug let empty wallets seize control of 82 Provenance assets

Trail of Bits says the flaw put token supply and about $500,000 of HASH escrow at risk; no exploitation was confirmed.

Security firm Trail of Bits disclosed an authorization flaw in the Provenance Blockchain that could let an account with no tokens take control of a marker’s admin, mint and withdrawal permissions. The vulnerability affected 82 live mainnet asset accounts, known as markers, which manage token supply, permissions and escrow balances.

How the bug worked

For non‑fixed markers, Provenance’s bank module tracks the live circulating supply, while the marker’s own supply field can remain at zero. The authorization check mistakenly read the stale marker field when verifying whether an account held the entire supply. Because both the stored supply and the attacker’s balance were zero, the check considered the condition satisfied and granted the permission change in a single transaction.

Assets at risk

All 82 affected markers had a zero stored supply but held real circulating supply or escrowed assets. The total escrow at risk was roughly 30 quadrillion nhash, valued at about $500,000 at the time of discovery. The largest holdings were in three Provenance Foundation programs:

  • grant0051 – ~19.23 quadrillion nhash
  • provenance.validator.incentive.program – ~8.56 quadrillion nhash
  • grant0077 – ~2.49 quadrillion nhash

A subset of 74 markers faced additional minting risk, including bridged stablecoins, wrapped assets, consortium deposits, tokenized mortgage participations and yield tokens. Examples are:

  • uusd.trading
  • uusdc.figure.se
  • nbtc.figure.se
  • cusd.deposit
  • cguaranteedrateomni
  • chomebridgeomni
  • nuva.ylds
  • uylds.fcc

Mitigation and timeline

Trail of Bits discovered the issue in March and reported it to Provenance on April 1. A zero‑supply guard released in v1.28.0 on May 1 blocked the vulnerable path for all identified markers. A second update in v1.29.0 on June 8 changed the authorization check to read the live supply from the bank module. GitHub records confirm the code changes were merged and released.

Current status

The disclosure does not indicate any confirmed exploitation, nor does it detail whether affected issuers or users were notified. The bug remains a notable example of how mismatched state records can create severe authorization risks in blockchain platforms.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
August 26, 2026, 8:10 AM
Original headline
A zero-balance bug let empty wallets seize control of 82 Provenance assets
View original report ↗