Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Provenance's marker module let anyone with zero tokens claim admin over 82 live financial assets

Trail of Bits found an authorization branch that compared a caller's balance against a supply figure the chain stops updating. Zero matched zero, and the check passed for everybody.

The Watch · Security desk

How we use AISend a correction

What happened

  • Trail of Bits reported a flaw in Provenance Blockchain's marker module that let any address grant itself admin rights over a token while holding none of it.
  • Eighty-two live mainnet markers held by multiple independent parties qualified, including bridged stablecoins, tokenized mortgage participations and yield tokens.
  • Taking the permission and acting on it required two transactions and no starting balance: one to add access, one to mint or to drain escrow.

Why it matters

  • exposure The richest reachable balances were the Provenance Foundation's own governance accounts for validator rewards and grant funds, so the cheapest theft ran through the entity that would have had to...
  • cost With no capital requirement, there was no economic friction to slow anyone who found the branch independently, and the eventual bill would have landed on issuers whose denominations were inflated.
  • constraint Where KYC restrictions blocked an attacker from spending minted tokens, the loss would still register as an accounting hole, which is harder to detect and slower to unwind than an emptied escrow.
  • precedent Any Cosmos SDK module that authorizes against its own stored copy of a figure the bank module actually owns can be talked into the same handover, which makes this a review pattern rather than one...

The condition that broke was not unreasonable on its face. If one address holds every unit of a token in circulation, treating it as the owner is defensible, and the `AddAccess` handler offered that as one of three sufficient tests, alongside being the designated manager of a `Finalized` marker or already holding `ACCESS_ADMIN` [6]. The defect is in where the denominator came from. `accountControlsAllSupply` calls `m.GetSupply`, which reads a supply field stored on the marker struct itself [7]. For markers whose supply is not fixed, the bank module is the source of truth and that field is only informational [5], and Provenance never writes back to it after minting [8]. A non-fixed marker activated with zero supply therefore reports zero supply for life, and the comparison resolves in favour of any caller with an empty balance [9].

That is the reusable lesson: a permission decision was made against a cached copy of a quantity another module owns [4][5]. Nothing in the marker's access control list was misconfigured, and no key was compromised.

Trail of Bits groups 74 of the 82 markers under the supply-inflation path [13][3], leaving eight described mainly through escrow, which is where the concrete money sat. Markers holding nhash in escrow came to roughly 30 x 10^15 nhash, about $500,000 at HASH prices when the bug was found [11]. The three largest are Provenance Foundation governance programs: one holding validator rewards, two holding community grant funds [12].

The mint path has no equivalent ceiling. An attacker holding `ACCESS_MINT` could issue arbitrary new tokens of the denom [14], and the denoms include bridged stablecoins and wrapped assets (`uusd.trading`, `uusdc.figure.se`, `nbtc.figure.se`), consortium deposits (`cusd.deposit`), tokenized mortgage participations (`cguaranteedrateomni`, `chomebridgeomni`), and yield tokens (`nuva.ylds`, `uylds.fcc`) [13]. Trail of Bits separates the two harms: for restricted tokens carrying KYC requirements the damage is to solvency and integrity, while non-restricted coin-type markers face direct inflation [15]. The second is a theft; the first is a discrepancy between what a registry says exists and what a servicer can account for, which tends to surface at reconciliation rather than at the block explorer.

The affected set was confirmed by querying mainnet through the Provenance CLI [16]. Worth sitting with: identifying every exploitable marker was a public read against the chain, requiring no insider knowledge of any issuer. Provenance shipped the correction in PR #2627 [19], 30 days after the April 1 report [17]. Everything before v1.28.0 carries the original check [2], and the date a fix is released is not the date a validator set runs it.

What to watch

  • Whether Provenance publishes upgrade coverage for v1.28.0 across its validator set, since any node below that version still runs the original check.
  • Whether other Cosmos SDK projects reuse the 100%-of-supply authorization shortcut against a locally stored supply value.
  • Whether on-chain history for any of the 82 markers shows the access path being exercised before the May 1 release.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence76
Adoption58
Hype gap−6
Incentives66
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Trail of Bits found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on the Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token.

    ReportedSupportedSource: Trail of BitsView cited source
  2. [2]

    The bug affects Provenance versions before 1.28.0; Trail of Bits found it in March 2026 and reported it to Provenance on April 1, 2026.

    ReportedSupportedView cited source
  3. [3]

    At the time of discovery, 82 active markers on Provenance mainnet had a stored supply of 0 while carrying real circulating supply or escrowed assets, and every one was exploitable; they span multiple independent parties on the chain, not a single application.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. blog.trailofbits.com

    1 article · August 25, 2026

    State divergence enables unauthorized access

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories