Register and share your invite link to earn from video plays and referrals.

GoPlus Security 🚦
@GoPlusSecurity
Protect Your Every Transaction. User App: 🛡️ Dev Integration: Security Intelligence & SafeToken Protocol 🛡️
Joined May 2021
1.1K Following    443.6K Followers
🚨 GoPlus Security Alert: Lending protocol @bonzo_finance was exploited due to an Oracle verification vulnerability, resulting in losses exceeding $9 million. The integrity of every price read by Bonzo Lend relies on BLS signature verification. In this incident, the field value of the BLS signature on the message was [0,0], i.e., a zero signature. The BLS signature verifier constructed a BLS pairing check based on the input and passed it to Hedera's pairing precompile (system contract 0.0.8). Because both the submitted signature point and the referenced committee public key resolved to zero (the "point at infinity"), the pairing equation trivially held true, and the precompile returned 1 (true). Simply put, an invalid BLS signature passed the oracle verifier's verification, after which the manipulated price was accepted and written on-chain, and subsequently consumed by Bonzo Lend. For more details, please refer to: The attacker then bridged the stolen assets (ETH and WBTC) to #Ethereum#. Attacker address: 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e
Show more