GoPlusSecurity: The loan agreement was attacked by a premonitioner to verify a loophole, resulting in a loss of over $9 million
GoPlusSecurity reported that a loan agreement had been attacked because of a leak in the prophecies, resulting in losses of over $9 million. The price-reading integrity of the agreement depended on the BLS signature certification. In this case, the BLS signature field in the message was [0,0], i.e., zero. The BLS signature certifier builds a BLS pairing check based on input and transmits it to Hedera for pre-compilation (system contract 0.0.8). The pre-compilation returns 1 (true) because both the points of signature submitted and the quoted Commission public key were analysed as zero (“infinity”) and were set up in conjunction with each other's trivially. In short, an invalid BLS signature was validated by a predictor certifier, subsequently accepted and written on the chain, and eventually consumed by Bonzo Lend. The attackers then took the stolen assets (ETH and WBTC) bridge to another address, 0xaf20d792a19d42dfffd697ceba6100291d96d93e。
