Root Cause: The "Point at Infinity" Exploit
Published 7/13/2026, 9:14:32 AM
On July 11, 2026, Bonzo Lend, the largest lending protocol on the Hedera network, lost approximately $9.05 million due to a critical vulnerability in the Supra oracle's signature verification mechanism [Source: https://x.com/ilmeaalim/status/2075905177203417317]. The exploit allowed an attacker to artificially inflate the price of the SAUCE token by 12 orders of magnitude, enabling them to borrow massive amounts of USDC and wHBAR against negligible collateral [Source: https://x.com/ilmeaalim/status/2075905177203417317].
Root Cause: The "Point at Infinity" Exploit
The vulnerability resided in Supra’s on-chain verifier contract (requireHashVerified_V2) on Hedera. The attacker exploited a mathematical quirk in how the contract handled BLS signatures:
- Zeroed Signature: The attacker submitted a price update with a zeroed BLS signature
[0,0]instead of a valid committee signature [Source: https://x.com/ilmeaalim/status/2075905177203417317]. - Verification Bypass: Supra’s verifier passed this zeroed signature and a zeroed committee public key to Hedera’s pairing precompile (system contract
0.0.8). - Trivial Satisfaction: Because both the signature and public key represented the "point at infinity," the BLS pairing equation was satisfied trivially. The precompile returned
true, causing the oracle to accept and write the manipulated price on-chain as "verified" [Source: https://x.com/ilmeaalim/status/2075905177203417317].
Exploit Timeline (July 11, 2026)
The attacker executed the exploit within a narrow window before legitimate oracle updates or protocol pauses could intervene.
| Time (UTC) | Event | Action Details |
|---|---|---|
| 00:39:53 | Collateral Deposit | Attacker deposits 250 SAUCE (worth ~$3.50) [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
| 00:51:39 | Price Manipulation | Attacker submits manipulated SAUCE price to Supra oracle [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
| 00:51:47 | First Borrow | Attacker borrows 6,634,528 USDC from Bonzo Lend [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
| 00:51:57 | Second Borrow | Attacker borrows 34,518,389 wHBAR (~$2.42M) [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
| 01:36:00 | Price Reset | Legitimate oracle update restores SAUCE to market price [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
| 01:41:00 | Protocol Pause | Bonzo Lend is officially paused to prevent further loss [Source: https://x.com/ilmeaalim/status/2075905177203417317]. |
Financial and Market Impact
The exploit had a devastating effect on the protocol's liquidity and the broader Hedera DeFi ecosystem:
- Total Stolen: Approximately $9.05 million was taken by the primary attacker (Wallet A) [Source: https://x.com/ilmeaalim/status/2075905177203417317].
- White-Hat Recovery: A second actor (Wallet B) borrowed roughly $1 million during the exploit window but later identified as a white-hat and coordinated the return of those funds [Verified: Multiple sources including Bonzo Finance confirm Wallet B returned the funds].
- TVL Collapse: Bonzo Lend's Total Value Locked (TVL) plummeted by 77% following the incident [Source: https://x.com/shuigvn/status/2076324120774778954].
- Ecosystem Impact: Hedera's overall DeFi TVL fell by approximately 40% within 24 hours [Note: not independently confirmed].
Supra Labs has since deployed a fix to the affected verifier contract on the Hedera mainnet to prevent similar cryptographic bypasses [Verified: Supra Labs official announcement]. While the vulnerability was in the oracle's verification logic, the incident highlighted a lack of secondary price safeguards or "sanity check" limits within Bonzo Lend's consumption of external data.