
What happened
Trail of Bits reported a vulnerability affecting 82arkers representing live financial assets on the mainnet.
Why it matters
The flaw affected administrative control over 82arkers representing live financial assets on the mainnet.
Trail of Bits reported a discovered vulnerability in Provenance Blockchain, a public proof-of-stake blockchain built on the Cosmos SDK. According to the firm, the flaw allowed any user to gain administrative control over marker accounts without owning tokens.
The vulnerability affected 82arkers representing live financial assets on the mainnet. Provenance is used for services including tokenized loans, private equity tokens, bridged assets, and asset registries.
Trail of Bits identified the issue in March 2026 and reported it to Provenance on April 1. According to the source, versions prior to 1.28.0 were vulnerable. The provided package contains no information regarding actual exploitation, remediation timelines, or the status of the affected markers.
Confirmed facts
- Trail of Bits reported a vulnerability in Provenance Blockchain.
- Provenance Blockchain is described as a public proof-of-stake blockchain based on the Cosmos SDK.
- The vulnerability allowed a user to gain administrative control over marker accounts without owning tokens.
- The issue affected 82arkers representing live financial assets on the mainnet.
- The vulnerability affected versions prior to 1.28.0.
- Trail of Bits discovered the issue in March 2026 and reported it to Provenance on April 1, 2026.
- Provenance covers tokenized loans on the blockchain, private equity tokens, bridged assets, and asset registries.
Context
The sole source is a Trail of Bits publication, presented in the package as primary material with metadata and an author synopsis. Independent confirmation is absent.
What remains unknown
- Was the vulnerability actually exploited before disclosure?
- Which version of Provenance resolves the issue, and have the affected systems been updated?
- Which specific marker accounts and financial assets were among the 82 objects?
- Has Provenance confirmed Trail of Bits' findings in an independent statement?
Editorial context
Confidence: high
The likely consequence is increased attention to access control in blockchain systems serving tokenized financial assets. The next observable signal will be a report from Provenance regarding a fix, version updates, or the status of the 82arkers. Significant uncertainty remains: the package does not confirm exploitation of the vulnerability and contains no response from Provenance.