Go to app

Root Cause: The "Point at Infinity" Exploit

Published 7/13/2026, 9:14:32 AM

On July 11, 2026, Bonzo Lend, the largest lending protocol on the Hedera network, lost approximately $9.05 million due to a critical vulnerability in the Supra oracle's signature verification mechanism [Source: https://x.com/ilmeaalim/status/2075905177203417317]. The exploit allowed an attacker to artificially inflate the price of the SAUCE token by 12 orders of magnitude, enabling them to borrow massive amounts of USDC and wHBAR against negligible collateral [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Root Cause: The "Point at Infinity" Exploit

The vulnerability resided in Supra’s on-chain verifier contract (requireHashVerified_V2) on Hedera. The attacker exploited a mathematical quirk in how the contract handled BLS signatures:

  • Zeroed Signature: The attacker submitted a price update with a zeroed BLS signature [0,0] instead of a valid committee signature [Source: https://x.com/ilmeaalim/status/2075905177203417317].
  • Verification Bypass: Supra’s verifier passed this zeroed signature and a zeroed committee public key to Hedera’s pairing precompile (system contract 0.0.8).
  • Trivial Satisfaction: Because both the signature and public key represented the "point at infinity," the BLS pairing equation was satisfied trivially. The precompile returned true, causing the oracle to accept and write the manipulated price on-chain as "verified" [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Exploit Timeline (July 11, 2026)

The attacker executed the exploit within a narrow window before legitimate oracle updates or protocol pauses could intervene.

Time (UTC)EventAction Details
00:39:53Collateral DepositAttacker deposits 250 SAUCE (worth ~$3.50) [Source: https://x.com/ilmeaalim/status/2075905177203417317].
00:51:39Price ManipulationAttacker submits manipulated SAUCE price to Supra oracle [Source: https://x.com/ilmeaalim/status/2075905177203417317].
00:51:47First BorrowAttacker borrows 6,634,528 USDC from Bonzo Lend [Source: https://x.com/ilmeaalim/status/2075905177203417317].
00:51:57Second BorrowAttacker borrows 34,518,389 wHBAR (~$2.42M) [Source: https://x.com/ilmeaalim/status/2075905177203417317].
01:36:00Price ResetLegitimate oracle update restores SAUCE to market price [Source: https://x.com/ilmeaalim/status/2075905177203417317].
01:41:00Protocol PauseBonzo Lend is officially paused to prevent further loss [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Financial and Market Impact

The exploit had a devastating effect on the protocol's liquidity and the broader Hedera DeFi ecosystem:

  • Total Stolen: Approximately $9.05 million was taken by the primary attacker (Wallet A) [Source: https://x.com/ilmeaalim/status/2075905177203417317].
  • White-Hat Recovery: A second actor (Wallet B) borrowed roughly $1 million during the exploit window but later identified as a white-hat and coordinated the return of those funds [Verified: Multiple sources including Bonzo Finance confirm Wallet B returned the funds].
  • TVL Collapse: Bonzo Lend's Total Value Locked (TVL) plummeted by 77% following the incident [Source: https://x.com/shuigvn/status/2076324120774778954].
  • Ecosystem Impact: Hedera's overall DeFi TVL fell by approximately 40% within 24 hours [Note: not independently confirmed].

Supra Labs has since deployed a fix to the affected verifier contract on the Hedera mainnet to prevent similar cryptographic bypasses [Verified: Supra Labs official announcement]. While the vulnerability was in the oracle's verification logic, the incident highlighted a lack of secondary price safeguards or "sanity check" limits within Bonzo Lend's consumption of external data.