A DeFi lending exploit traced to an oracle verifier that accepted a zeroed signature and public key, letting a forged price pass as valid.

On July 11th, 2026, Bonzo Finance's Hedera lending market, Bonzo Lend, lost approximately $9.05 million when an attacker manipulated the on-chain price feed for SAUCE and borrowed far beyond what a $3 deposit should have supported. This was not a flash loan attack, not a reentrancy exploit, and not a compromise of any private key or wallet. The lending pool's own contracts never malfunctioned, they read a number from Bonzo Lend's configured price oracle and computed collateral value exactly as designed. The actual failure sat one layer upstream, inside the verification logic of Supra's on-chain oracle, where a price update carrying no real signature at all was accepted as genuine.
Bonzo Lend prices its markets using two third-party oracle providers on Hedera, Chainlink and Supra. Chainlink covers HBAR and USDC. Every other supported asset, including SAUCE and WHBAR, is priced exclusively through Supra, which runs on a push model. Supra's oracle committee periodically publishes signed price updates directly to on-chain storage, and Bonzo Lend simply reads the latest stored value, it never submits a price or requests one on demand. Before Supra's contracts accept a new price into that storage, the feed's verifier contract, requireHashVerified_V2, is supposed to confirm the update carries a valid BLS signature from an authorized committee member, checked using Hedera's pairing precompile at system contract 0.0.8. Every dollar of borrowing capacity Bonzo Lend calculates for SAUCE and WHBAR depends on that single check holding.
At 00:39:53 UTC on July 11th, a wallet later identified as the attacker, Wallet A, deposits 250 SAUCE, worth roughly $3 at the time, into Bonzo Lend as collateral.

Around 00:40:00, the same wallet submits a first, normal-valued price update to Supra's on-chain pull contract, consistent with probing the submission path before the real attempt.

At 00:51:39 UTC, Wallet A submits a manipulated update for oracle pair 425, SAUCE/wHBAR, referencing committee ID 2, a committee hash of 0xd4e6b48aef731cc8cd74b25fbaec267ff8a6269aea1f4be4ee19dda5ecbf3f7f, and a BLS signature field set to [0,0], a value no legitimate signature scheme produces.


Because committee ID 2 falls outside the range Supra's verifier had actually populated, the lookup returns a public key of all zeros instead of rejecting the reference, so requireHashVerified_V2 hands a zero signature and a zero key to Hedera's pairing precompile at system contract 0.0.8.
Both sides of a BLS pairing equation resolve to the identity element under those inputs, so the precompile correctly answers that the equation holds, and the verifier accepts the update as a genuine committee signature, writing SAUCE's on-chain price as 1 followed by thirty zeroes, roughly twelve orders of magnitude above its real value of about 0.2 HBAR.

Eight seconds later, at 00:51:47, Wallet A borrows 6,634,528.202695 USDC from Bonzo Lend against a SAUCE position the protocol now values as if it were worth tens of millions of dollars.

Ten seconds after that, at 00:51:57, Wallet A borrows an additional 34,518,389.36109841 WHBAR from the same pool, using the same inflated collateral.

Between roughly 01:11 and 01:36 UTC, a second wallet, Wallet B, deposits its own SAUCE and borrows further assets while the manipulated price is still live on-chain. Wallet B later contacts the Bonzo team directly, identifies itself as a white-hat responder, and states its intention to return the funds.


At 01:36 UTC, Supra's next scheduled legitimate price publication overwrites the manipulated value, restoring SAUCE to its real price of approximately 0.1964 HBAR. Bonzo Lend is paused five minutes later, at 01:41, and Bonzo Points is paused separately at 05:50 as the team begins its investigation.
This was not a bug in Bonzo Lend's own contracts and not the result of market manipulation, SAUCE's real trading price never moved during the window, and no flash loan appears anywhere in the attack sequence. The exploit came from Supra's oracle verifier accepting a signature and public key that were both the BLS identity element, which produced a pairing check that was mathematically correct but proved nothing about authorization.
requireHashVerified_V2 never checked that the submitted signature and referenced public key were non-zero and properly on-curve before handing them to the pairing precompile.Third-party verifier review. Bonzo Lend's own contracts were sound, but the protocol's borrowing capacity depended entirely on a verifier it did not own or control. A dependency-boundary review that traces every price an integration reads back to the verification code that produced it, including requireHashVerified_V2 itself, would have surfaced the missing zero-element check before it reached production, regardless of which team owned the repository.
Price deviation circuit breakers. A sanity check comparing each new oracle read against its trailing value, and rejecting or flagging any update that moves price past a defined threshold, would have caught a jump of twelve orders of magnitude in eight seconds regardless of whether the underlying signature check was valid.
Redundant feeds for every borrowable asset. HBAR and USDC carried both Chainlink and Supra coverage; SAUCE and WHBAR did not. Extending redundant oracle coverage to every asset accepted as collateral, with a cross-check between sources before a price is trusted, removes any single oracle's verifier from being a single point of failure for the whole pool.
Stolen funds were bridged to Base and Arbitrum via Stargate and Across Protocol, eventually consolidated on Ethereum and deposited into Tornado Cash.



Bonzo paused Bonzo Lend on July 11th, citing volatile markets, without naming a cause or a dollar figure.
Hours later, Bonzo confirmed the pause and published its full incident report with a detailed technical breakdown.
Hedera confirmed Supra had acknowledged the exploit and deployed a fix, stating Bonzo Lend's own contracts functioned exactly as designed.
Supra published its own incident report, confirming a patched verifier with range validation and rejection of zero or off-curve inputs.
On July 16th, Bonzo Finance Foundation announced it will fund full recovery of affected positions, backed by a Hedera Foundation recovery facility.
Attacker Wallets
Post-Bridge Wallet (Ethereum)
White-Hat Responder
Vulnerable Third-Party Oracle Contracts
Bonzo Finance Contracts
Key Transactions
No signature was forged and no key was cracked. Supra's verifier accepted a zeroed signature and public key, and the resulting pairing check correctly returned true, trusting a correct answer to the wrong question. Bonzo Lend's own contracts never malfunctioned, they simply read the price they were handed. Supra has patched the verifier, and Bonzo Finance Foundation, backed by Hedera Foundation, is funding full recovery for affected users. A correct answer to the wrong question is still the wrong answer.
Contents


From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.