Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

A Single Zeroed-Out Signature Drained $9M from Hedera's Bonzo Lend — Here's How It Happened

(81 days ago) · 1 source · Summarized by CryptoBipto

A critical vulnerability in the oracle signature validation of Bonzo Lend, a DeFi lending protocol on the Hedera network, allowed an attacker to exploit a zeroed oracle signature and drain approximately $9 million in funds. The exploit highlights ongoing smart contract security risks even on newer blockchain networks like Hedera.

WHY IT MATTERS

Think of an oracle like a trusted price reporter that tells a lending app how much your crypto collateral is worth. If someone can fake that reporter's credentials — in this case by submitting an empty, zeroed-out digital signature that the system mistakenly accepted — they can trick the app into thinking assets are worth more (or less) than they really are, and drain funds. This exploit is a reminder that even on newer, supposedly more secure blockchains, the apps built on top of them can still have critical bugs. If you're using DeFi lending platforms, it's important to check whether they've been thoroughly audited and to never invest more than you can afford to lose.

The exploit centered on a flaw in how Bonzo Lend validated oracle price feed signatures. Oracles are essential components in DeFi lending protocols — they provide real-time price data that determines how much users can borrow and when loans should be liquidated.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

SOURCES

  • Source

RELATED

HBARDeFi SecurityOracle ExploitsSmart Contract VulnerabilitiesHedera EcosystemLending Protocols