A zero-balance bug let empty wallets seize control of 82 Provenance assets
Trail of Bits disclosed a Provenance Blockchain authorization flaw that it stated uncovered 82 reside mainnet asset accounts to takeover. A profitable abuse may let somebody mint an affected token or withdraw assets held in escrow.
Those particular asset accounts, known as markers, govern a token’s provide, permissions, and escrow stability. The safety agency stated the flaw allowed a consumer who held none of a marker’s tokens to take its admin, mint, and withdrawal permissions, then act on them in a second transaction.
The bug got here from a mismatch between two records of token provide. For non-fixed markers, Provenance’s financial institution module tracks reside circulating provide, whereas the marker’s provide subject can stay at zero.
The authorization examine learn the stale marker subject when testing whether or not an account held the complete provide. Because a brand new account’s stability was additionally zero, the examine handled zero as equal to zero and accredited the permission change.
Trail of Bits stated all 82 affected markers had zero saved provide whereas carrying actual circulating provide or assets in escrow.
The disclosed affected nhash escrow totaled roughly 30 quadrillion nhash, value about $500,000 at HASH costs when the problem was found. Three Provenance Blockchain Foundation packages held most of it: grant0051 held about 19.23 quadrillion nhash, provenance.validator.incentive.program held about 8.56 quadrillion, and grant0077 held about 2.49 quadrillion.
A distinct 74-marker token subset, included inside the whole of 82, confronted unauthorized minting danger. It spanned bridged stablecoins and wrapped assets, consortium deposits, tokenized mortgage participations, and yield tokens.
Named examples included uusd.buying and selling, uusdc.determine.se, nbtc.determine.se, cusd.deposit, cguaranteedrateomni, chomebridgeomni, nuva.ylds, and uylds.fcc.
Trail of Bits described a direct inflation danger for unrestricted coin-type markers. Restricted tokens with id necessities confronted supply-integrity and solvency dangers even when an attacker couldn’t freely switch newly created items.

Trail of Bits stated it found the flaw in March and reported it to Provenance on April 1. It stated a zero-supply guard launched with v1.28.0 on May 1 blocked the reported path towards all 82 recognized markers.
A second change made the authorization examine learn reside provide from the financial institution module, and the challenge included it in v1.29.0 on June 8.
GitHub data present the code modifications had been merged and launched. The Trail of Bits disclosure doesn’t say whether or not chain evaluation discovered unauthorized entry, minting, or withdrawals, or whether or not it notified affected issuers and customers.
The submit A zero-balance bug let empty wallets seize control of 82 Provenance assets appeared first on CryptoSlate.
