A Single Zeroed-Out Signature Drained $9M from Hedera's Bonzo Lend — Here's How It Happened
10d ago · 1 source
A critical vulnerability in the oracle signature validation of Bonzo Lend, a DeFi lending protocol on the Hedera network, allowed an attacker to exploit a zeroed oracle signature and drain approximately $9 million in funds. The exploit highlights ongoing smart contract security risks even on newer blockchain networks like Hedera.
WHY IT MATTERS
Think of an oracle like a trusted price reporter that tells a lending app how much your crypto collateral is worth. If someone can fake that reporter's credentials — in this case by submitting an empty, zeroed-out digital signature that the system mistakenly accepted — they can trick the app into thinking assets are worth more (or less) than they really are, and drain funds. This exploit is a reminder that even on newer, supposedly more secure blockchains, the apps built on top of them can still have critical bugs. If you're using DeFi lending platforms, it's important to check whether they've been thoroughly audited and to never invest more than you can afford to lose.
Read the full analysis with a CryptoBipto membership
Create a free account and subscribe to unlock deep-dive analysis on every story.
Get startedSOURCES
RELATED
Educational only — not financial advice.
