Skip to main content
6 min read

Bonzo Lend Exploit: $9.05M
Borrowed via Oracle Zero-Signature Bypass

$9.05 million in principal was extracted from Bonzo Lend after Supra's oracle verifier accepted a zeroed BLS signature, inflating SAUCE collateral by 12 orders of magnitude.

AUTOSEC.DEVAUTOSEC.DEV
Bonzo Lend Exploit: $9.05M Borrowed via Oracle Zero-Signature Bypass
  • Incident Date: July 11, 2026
  • Target: Bonzo Lend
  • Target Overview: Bonzo Lend is an open-source, non-custodial lending and borrowing protocol adapted from Aave for Hedera EVM and Hedera Token Service assets. The affected pool used third-party oracle data to value collateral and determine borrowing capacity.
  • Total Loss: Approximately $9.05 million in borrowed principal from the primary attacker
  • Primary Attacker Account: 0.0.10633526 (0x9a4966152f6e10b33cb7a37975e8619816d6a494)
  • Manipulated Price Transaction: 0.0.995584-1783731093-686041919 (0xd50c55e24eb8483ec55bf74e84fc9853d0f0fe36f64abdb812a2d9afa2a10a60)
  • Affected Oracle Contracts: Supra pull oracle 0.0.4323024; verifier 0.0.4323006
  • Attack Vector: Oracle manipulation / signature verification bypass through BLS zero-signature acceptance

Incident Review & Technical Details

1. Attack Path

  1. The attacker prepared a small SAUCE position: At 00:39:53 UTC, the primary attacker deposited 250 SAUCE, worth only a few dollars at the real market price, into Bonzo Lend as collateral. A normal-valued oracle update followed seven seconds later in what Bonzo Finance Labs described as possible reconnaissance.
  2. A fabricated price entered Supra's pull oracle: At 00:51:39 UTC, the attacker submitted a SAUCE/WHBAR price update for oracle pair 425. SAUCE was trading near 0.2 HBAR, but the submitted price field contained the integer 1 followed by 30 zeroes, inflating the reported value by roughly 12 orders of magnitude.
  3. A zeroed BLS signature passed verification: The update named committee ID 2 and supplied [0,0] where the committee's BLS signature should have been. According to Bonzo's preliminary report, Supra's verifier did not reject zero or identity points or perform the required subgroup checks before calling Hedera's pairing precompile. Because both the signature point and referenced committee public key were the point at infinity, the pairing equation resolved to the identity and the precompile correctly returned true; the verifier incorrectly treated that result as proof of an authorized signature.
  4. Bonzo Lend accepted the poisoned price: The manipulated value was written to the oracle's on-chain storage. Bonzo Lend then read that stored value and applied its configured loan-to-value rules. The lending contracts behaved deterministically, but the upstream data they trusted had already passed a defective authentication check.
  5. The attacker borrowed $9.05 million in principal: Eight seconds after the false price landed, the attacker borrowed 6,634,528.202695 USDC. Ten seconds later, the same account borrowed 34,518,389.36109841 WHBAR. Using Bonzo's incident-time reference prices, the primary attacker extracted approximately $9.05 million.
  6. Part of the proceeds moved to Ethereum: Early on-chain tracking from Specter and PeckShield followed assets bridged from Hedera to Ethereum through LayerZero and swaps from WBTC into ETH. PeckShield's snapshot identified approximately $5.25 million already bridged, while later reporting tracked more than $5.8 million. These figures measured observed cross-chain movement at different times, not the final protocol-level loss.

2. Impact Scope

  • Protocol-Level Loss: The primary attacker extracted approximately $9.05 million in borrowed principal from Bonzo Lend. This is the canonical headline impact published by Bonzo Finance Labs.
  • Additional Abnormal Borrowing: A second account borrowed roughly $1 million while the manipulated price remained live. That wallet contacted the team, identified itself as a white-hat responder, and stated that it intended to return the assets. Bonzo therefore excluded it from the headline loss and classified it as a recovery item; completion of the return had not been confirmed in the reviewed sources.
  • Affected Products: Bonzo Lend and Bonzo Points were paused. Bonzo Vaults, Bonzo Bridge, and single-sided BONZO/XBONZO staking were reported as unaffected and continued operating.
  • Hedera Network Scope: Hedera's consensus mechanism and core network services were not reported as compromised. The pairing precompile returned the result specified for the mathematical inputs it received; the missing security checks were in the third-party verifier that interpreted that result.
  • SaucerSwap Scope: No reviewed evidence supports an exploit of SaucerSwap or a manipulation of SAUCE's real market price. Early reports that called this a "Sauce Protocol" hack conflated the collateral token with the affected lending protocol.

3. Official Statements

  • Bonzo Finance Labs: In a preliminary incident report, the team attributed the failure to the third-party oracle verification path, set the primary impact at approximately $9.05 million, and said Bonzo Lend would remain paused while recovery and withdrawal plans were evaluated.
  • Hedera: In an updated statement, Hedera said the incident affected Bonzo Lend, an independently operated DeFi application, while its consensus mechanism, core network services, and mainnet operation remained intact.
  • Supra: According to Bonzo's report, Supra acknowledged the verifier issue and deployed a fix to the affected contract on Hedera mainnet.

4. Investigation Progress

Legitimate oracle publishing restored SAUCE to approximately 0.1964 HBAR at 01:36 UTC, and Bonzo Lend was paused five minutes later. The team was coordinating with the second wallet over the promised return of roughly $1 million, but its preliminary report did not yet cover reimbursement, liquidity-provider withdrawals, or a timetable for reopening.

On Ethereum, early investigators linked the flow to 0x9A49...a494 and the aggregation address 0xaf20...D93e. The latter was initially funded with 1 ETH from Tornado Cash and, at one PeckShield tracking snapshot, held approximately 2,360 ETH and 15.58 WBTC. This describes the address's initial funding and observed balances; it does not identify who controlled the account. No confirmed recovery of the primary attacker's approximately $9.05 million was identified in the reviewed sources.


AUTOSEC.DEV Solution

The Bonzo Lend incident shows why cryptographic input validation and lending-market oracle controls must be tested as one trust boundary, even when each application contract follows its programmed logic.

  1. Secure Code Review - Supra's verifier accepted zero or identity points before treating a successful pairing result as an authorized BLS signature. AUTOSEC.DEV reviews cryptographic verification paths, precompile edge cases, signature normalization, subgroup validation, and fail-closed behavior to catch exactly this class of authentication bypass.
  2. Security Strategy & Planning - One accepted SAUCE update inflated collateral value by roughly 12 orders of magnitude and unlocked approximately $9.05 million in borrowing. For lending markets such as Bonzo Lend, AUTOSEC.DEV designs defense-in-depth controls including cross-feed corroboration, deviation bounds, per-asset borrow caps, circuit breakers, and incident-specific pause criteria.
  3. Penetration Testing - The exploit required no flash loan and only two critical actions: write a poisoned oracle value, then borrow against it. AUTOSEC.DEV reproduces zero-signature, identity-point, stale-price, and extreme-deviation cases in forked environments to verify that oracle adapters and lending limits reject adversarial updates before funds can leave the pool.

Reference