A zero-balance bug let empty wallets seize control of 82 Provenance assets

Trail of Bits disclosed a Provenance Blockchain authorization flaw that it said exposed 82 live mainnet asset accounts to takeover. A successful abuse could let someone mint an affected token or withdraw assets held in escrow.
Those special asset accounts, called markers, govern a token's supply, permissions, and escrow balance. The security firm said the flaw allowed a user who held none of a marker's tokens to take its admin, mint, and withdrawal permissions, then act on them in a second transaction.
The bug came from a mismatch between two records of token supply. For non-fixed markers, Provenance's bank module tracks live circulating supply, while the marker's supply field can remain at zero.
The authorization check read the stale marker field when testing whether an account held the entire supply. Because a new account's balance was also zero, the check treated zero as equal to zero and approved the permission change.
Trail of Bits said all 82 affected markers had zero stored supply while carrying real circulating supply or assets in escrow.
โฆ Continue reading the full article at the original source below.



