Trail of Bits reported a discovered vulnerability in Provenance Blockchain, a public proof-of-stake blockchain built on the Cosmos SDK. According to the firm, the flaw allowed any user to gain administrative control over marker accounts without owning tokens.

The vulnerability affected 82arkers representing live financial assets on the mainnet. Provenance is used for services including tokenized loans, private equity tokens, bridged assets, and asset registries.

Trail of Bits identified the issue in March 2026 and reported it to Provenance on April 1. According to the source, versions prior to 1.28.0 were vulnerable. The provided package contains no information regarding actual exploitation, remediation timelines, or the status of the affected markers.