A zero-balance bug let empty wallets seize control of 82 Provenance assets

Share

Trail of Bits disclosed an authorization flaw on Provenance Blockchain that exposed 82 live mainnet asset accounts to takeover by users holding no tokens. The bug stemmed from a mismatch between two records of token supply: the bank module tracked live circulating supply while the marker supply field could remain at zero, causing the authorization check to read the stale field and treat a zero balance as equal to zero supply. Seventy-four markers faced unauthorized minting risk spanning bridged stablecoins, wrapped assets, consortium deposits, tokenized mortgage participations, and yield tokens, while roughly $500,000 in HASH sat in escrow across three programs. The fixes released in v1.28.0 and v1.29.0 blocked the reported path, but the disclosure does not establish whether attackers accessed, minted, or withdrew assets.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles