Go to app

The Bonzo Lend Exploit Mechanism

Published 7/13/2026, 6:10:15 PM

The Bonzo Lend oracle exploit on July 11, 2026, resulted in a $9.05 million loss but did not expose systemic risks within the Hedera core network. The incident was a technical failure of a third-party oracle provider, Supra, rather than a vulnerability in Hedera's consensus mechanism or Bonzo Lend's smart contracts [Source: https://x.com/Cosmideus/status/2075948541810454647].

The Bonzo Lend Exploit Mechanism

The exploit targeted Bonzo Lend, Hedera's largest lending protocol, by manipulating the Supra oracle pull contract. The attacker used a specific technical flaw in how signatures were verified:

  • The Attack: The exploiter deposited a negligible amount of SAUCE tokens (approx. 250 tokens) and submitted a manipulated price update [Source: https://x.com/ilmeaalim/status/2075905177203417317].
  • Technical Root Cause: Supra's verifier contract incorrectly validated a zeroed BLS signature ([0,0]). Because both the signature and the committee public key resolved to the "point at infinity," Hedera's pairing precompile (system contract 0.0.8) returned true, satisfying the verification check [Source: https://x.com/ilmeaalim/status/2075905177203417317].
  • Financial Impact: This manipulation inflated the price of SAUCE by 12 orders of magnitude. This allowed the attacker to borrow approximately 6.6 million USDC and 34.5 million wHBAR against the near-worthless collateral [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Systemic Risk Assessment

While the exploit caused a significant drop in Total Value Locked (TVL) on the network, research indicates the risk was isolated to the oracle integration layer rather than the Hedera network itself.

MetricImpactSystemic Risk?
Hedera Core NetworkNo impact on consensus or block production.No
Bonzo Lend ContractsFunctioned as designed; the math was correct, but the input (price) was false.No
Oracle InfrastructureFailure in Supra's signature verification logic on Hedera.Yes (Oracle-specific)
Hedera DeFi TVLDropped ~40% in 24 hours ($25.7M remaining).Partial (Sentiment)

[Source: https://x.com/shuigvn/status/2076324120774778954]

Current Status and Recovery

The exploit led to a 77% decline in Bonzo Lend's TVL and a broader 40% decline in Hedera's ecosystem TVL within 24 hours [Source: https://x.com/shuigvn/status/2076324120774778954].

  • Fix Deployed: Supra has since deployed a fix to the affected verifier contract on the Hedera mainnet to prevent zeroed signature validation [Source: https://x.com/ilmeaalim/status/2075905177203417317].
  • Protocol Status: Bonzo Lend's lending and points systems remain paused, though vaults, bridges, and staking are operational.
  • White-hat Activity: A second wallet (Wallet B) secured approximately $1 million during the exploit and has identified as a white-hat responder; coordination for the return of these funds is ongoing [Source: https://x.com/ilmeaalim/status/2075905177203417317].

In summary, the event highlights the "oracle risk" inherent in DeFi protocols but does not suggest a fundamental flaw in Hedera's underlying Hashgraph technology. The primary gap remains the lack of a finalized user compensation plan for those affected by the $9.05 million drain.