🚨 GoPlus Security Alert:
Lending protocol
@bonzo_finance was exploited due to an Oracle verification vulnerability, resulting in losses exceeding $9 million.
The integrity of every price read by Bonzo Lend relies on BLS signature verification. In this incident, the field value of the BLS signature on the message was [0,0], i.e., a zero signature. The BLS signature verifier constructed a BLS pairing check based on the input and passed it to Hedera's pairing precompile (system contract 0.0.8). Because both the submitted signature point and the referenced committee public key resolved to zero (the "point at infinity"), the pairing equation trivially held true, and the precompile returned 1 (true).
Simply put, an invalid BLS signature passed the oracle verifier's verification, after which the manipulated price was accepted and written on-chain, and subsequently consumed by Bonzo Lend.
For more details, please refer to:
The attacker then bridged the stolen assets (ETH and WBTC) to #
Ethereum#.
Attacker address:
0xaf20D792A19fD42dCf697ceBa6100291D96dD93e