Hedera's Largest Lending Protocol Loses $9 Million After Oracle Flaw Accepts a Fake Signature
A cryptographic verification bug in Supra's price oracle allowed an attacker to inflate a token's price by many orders of magnitude and drain Bonzo Lend in under 18 seconds on July 11, 2026.
Bonzo Lend, the largest decentralized lending protocol on the Hedera network, was drained of approximately $9.05 million early Friday morning after an attacker exploited a signature verification flaw in Supra's price oracle infrastructure. The incident, which unfolded on Hedera mainnet between roughly 00:39 and 01:36 UTC, sent Hedera's total DeFi value locked down roughly 40 percent within 24 hours, falling from around $43 million to $25.7 million. Bonzo Lend's own TVL dropped 77 percent. In response, Bonzo Lend was paused; Bonzo Vaults, Bonzo Bridge, and BONZO/XBONZO staking were unaffected and remained fully operational.
How the Attack Worked
The attacker's entry point was SAUCE, the governance token of SaucerSwap, Hedera's largest decentralized exchange. At the time of the exploit, SAUCE was trading at approximately 0.1964 HBAR, or about $0.014, with a total market cap around $12.2 million. Its low liquidity made it an attractive manipulation target.
Supra operates what is called a "pull oracle" model: rather than continuously broadcasting price data on-chain, price updates are submitted only when a protocol needs them, and a verifier contract checks that each submission carries a valid cryptographic signature from Supra's authorized committee. That signature check is where the attack landed.
At 00:51:39 UTC, the attacker submitted a manipulated price update carrying a completely zeroed BLS signature, a cryptographic signature type where all values were set to zero. In elliptic curve cryptography, a signature with all zeroed values corresponds to the identity element of the curve, sometimes called the "point at infinity."
When Hedera's pairing precompile computed the mathematical check on this submission, it returned a technically correct result for that specific equation. Supra's verifier contract then read that result as proof of a valid signature. As Bonzo Finance Labs put it in their incident report: "The verifier trusted a correct answer to the wrong question."
The forged update inflated SAUCE's reported price by many orders of magnitude above its real value.
The attacker had pre-positioned 250 SAUCE tokens as collateral in the protocol at 00:39:53 UTC, roughly 12 minutes before the manipulated price update was submitted. Those tokens were worth only a few dollars at market price. Within eight seconds of the false price going live, that pre-positioned collateral was used to borrow 6,634,528 USDC and 34,518,389 WHBAR (wrapped HBAR). Both borrows were complete within 18 seconds of the manipulated update. A legitimate oracle update restored the correct price at 01:36 UTC.
Bonzo Lend was paused five minutes later.
Bonzo Finance was clear in its post-mortem that its own smart contracts performed as intended. The protocol's lending logic correctly processed the price data it received. The failure originated entirely in Supra's verification layer.
Stolen Funds Cross Chains
On-chain security firm PeckShield tracked $5.25 million of the stolen funds moving from Hedera to Ethereum via the LayerZero cross-chain bridge shortly after the exploit. The attacker's Ethereum wallets were observed holding approximately 2,284 ETH (around $4.11 million) and 15.58 WBTC (around $1 million), with the WBTC subsequently converted to ETH. PeckShield's confirmed figure reflects funds bridged to Ethereum and does not account for the full $9.05 million loss; on-chain tracking of the remaining funds was ongoing at time of publication. The attacker had pre-funded a wallet with 1 ETH sourced from Tornado Cash, a cryptocurrency mixer, roughly ten hours before the attack.
A second wallet was also active during the false-price window, borrowing approximately $1 million in assets. That wallet contacted Bonzo Finance through Discord, identified itself as a white-hat responder acting to protect the protocol, and pledged to return the funds. Bonzo's incident report excluded that $1 million from the confirmed loss figure while the return remains pending.
Supra acknowledged the vulnerability after the incident and said a patch had been deployed to the affected verifier contract on Hedera mainnet, according to multiple reports.
What This Means Beyond the Exploit
The Hedera network carries particular significance in emerging markets. Standard Bank, Africa's largest bank by assets with roughly 20 million customers across 27 countries, holds a seat on the Hedera Governing Council and has been piloting stablecoin-based remittances on Hedera's Token Service alongside Shinhan Bank and SCB TechX.
The HBAR Foundation has actively promoted Hedera as infrastructure for financial inclusion across Africa, a region where traditional banking reaches fewer than half the population.
A 40 percent single-day collapse in Hedera's DeFi TVL is unlikely to disrupt those institutional pilots directly, since they operate on separate Hedera services that were not affected by the exploit. It does, however, raise the stakes for developer confidence in Hedera-native DeFi at a time when the network is being positioned as a credible alternative financial rail.
The Broader Oracle Warning
This attack did not require a flash loan or any real price movement in the market. It required only a broken verification path. For developers building DeFi protocols on non-EVM networks, including Hedera, Solana, NEAR, and Algorand, where pull-oracle models are increasingly common, the case illustrates a distinct risk category: the oracle's data pipeline itself can be the vulnerability, independent of market conditions.
Straightforward defenses would have blocked this specific attack: a simple check rejecting any submitted signature with zero values, independent price deviation limits, or a multi-oracle setup drawing from more than one provider. None of those safeguards were in place.
Bonzo Lend remains paused with no reopening timeline announced as of publication.