CryptoReal
CASE FILE — Jul 14, 2026

Bonzo Lend Loses $9.05 Million After Oracle Verifier Accepts a Blank Signature

A cryptographic identity turned out to be the only thing standing between Hedera's largest lending market and a $9.05 million loss. Nothing was forged and no private key was stolen — the exploit worked because a check that should have run simply never fired.

On July 11th, an attacker deposited 250 SAUCE tokensworth roughly $3 — into Bonzo Lend, then pushed through a price update valued twelve orders of magnitude above reality. Eight seconds later, that inflated collateral had unlocked 6.63 million USDC and 34.5 million WHBAR from the protocol's reserves.

There was no flash loan and no reentrancy trick involvedthe signature check itself was never actually performed. Supra's oracle verifier waved through a malformed update, its pairing check returning "true" for input that should have failed outright. Bonzo's smart contracts then acted on the price they were given, exactly as designed. The underlying precompile computed the correct answer to a question the verifier should never have asked it in the first place — the failure was upstream, in what was allowed to reach that computation.

01Timeline of the drain

At 00:39 UTC on July 11th, an account later labeled "Wallet A" deposited 250 SAUCE into Bonzo Lend, a position worth about $3 and unremarkable enough to draw no attention. Twelve minutes on, the same wallet submitted a price update to Supra's on-chain oracle. SAUCE, normally trading around a penny and a half, was suddenly quoted at twelve orders of magnitude above its real value. Eight seconds after that update landed, 6.63 million USDC and 34.5 million WHBAR flowed out of the pool.

Bonzo's official channels were first to acknowledge trouble, but with almost no detail — a note about "investigating volatile markets" and a link to a status page, without a dollar figure or the word "exploit." Independent researchers moved faster: on-chain investigator Specter published the first real breakdown, describing an apparent hack on the Hedera network with over $3.7 million already bridged to Ethereum via LayerZero and stolen funds being converted from WBTC into ETH. Specter's running estimate climbed in subsequent posts — past $4 million, then past $5 million — before confirming that proceeds were being routed into Tornado Cash.

Bonzo's own accounting followed, ultimately settling on $9.05 million taken by the attacker, plus roughly $1 million more attributed to a self-described white-hat responder. Hedera's team was quick to draw a distinction that no one else had yet made explicit: "Hedera's consensus mechanism and core network services were not compromised, and mainnet remained operational." Responsibility, in Hedera's telling, sat with a third-party oracle verifier — and Hedera publicly named Supra a full day before Supra itself issued any statement.

By 09:49 UTC, Bonzo had released its complete incident report, eventually documenting every wallet, timestamp, and the zeroed-out signature at the center of it all. SlowMist founder Cos summarized the mechanism concisely: the attacker's signature and public key were both zero, meaning "both sides of the underlying mathematical verification equation simultaneously became 0" — and the check passed regardless. QuillAudits meanwhile traced the money through addresses and transaction hashes, mapping a route through Arbitrum, Base, and Ethereum before it reached Tornado Cash — the same laundering pattern seen in countless prior incidents, just executed a bit differently this time.

02A two-year-old gap

Supra runs a "pull" oracle model, where anyone can submit a price update as long as an accompanying proof clears a BLS signature check processed through Hedera's pairing precompile. In this case, the attacker referenced a committee ID that fell outside the range Supra had actually configured. Rather than rejecting that out-of-range reference, the lookup silently returned an all-zero public key. Because zero is the BLS identity element, pairing a zero signature with a zero key satisfies the verification equation automatically — the precompile answered truthfully, but the verifier had failed to screen out that degenerate input beforehand.

Supra's postmortem lays out the fix plainly: three new checks now exist where none stood before — range validation on committee lookups, explicit rejection of identity-element keys and signatures, and on-curve validation ahead of the pairing check itself. As Supra put it: "The identity-element check alone would have prevented this attack."

What sets this incident apart is what happened next. Supra co-founder and CEO Joshua Tobkin addressed the attacker(s) directly on social media, and buried within that message is a detail that recasts the whole story: the flawed verifier code had sat live, unpatched, and fully visible on-chain for two years. "Live. Transparent. For two years straight," Tobkin wrote — spanning an entire bull market — before adding: "Anyone could have found it. Nobody did. Not until now."

Tobkin's explanation for the timing points to AI-assisted code review — a new category of adversary that "reads every line, every branch, every edge case" with a persistence no human auditor can match. Regardless of whether this specific exploit actually originated from AI-assisted analysis, the claim raises an uncomfortable possibility: protocols reviewed only by human teams may have been vetted against a threat model that no longer reflects reality.

03Chasing the money

Within minutes of the drain, a portion of the stolen funds was already leaving Hedera via LayerZero, with Stargate identified by QuillAudits as the bridge used to move funds across Arbitrum, Base, and Ethereum. By the time it settled, the receiving wallet held approximately $5.25 million — close to 2,360 ETH and 15.58 WBTC — with WBTC and stablecoin holdings progressively converted into ETH, all inside a window shorter than a typical coffee break.

PeckShield noted that this same receiving wallet had been funded ten hours earlier with a single ETH sourced from Tornado Cash, a pattern suggesting operational experience rather than a first attempt.

Sums referenced in this case file

Key on-chain identifiers:

Manipulated price update — Hedera Transaction ID: 0.0.995584-1783731093-686041919; EVM-compatible hash: 0xd50c55e24eb8483ec55bf74e84fc9853d0f0fe36f64abdb812a2d9afa2a10a60

Wallets:

Contracts:

Every one of these identifiers is publicly viewable on HashScan or Etherscan, yet as of this writing, no one has attached a real-world identity to the wallet holding the stolen funds.

That anonymity is the backdrop against which Tobkin negotiated openly on Twitter, addressing the attacker directly. The offer was straightforward: keep $100,000, return the remainder, and walk away with no charges and a standing job offer. Refuse, and a bounty on the attacker would grow 10% annually, indefinitely, payable to whoever eventually identifies them. The deadline given was seventy-two hours, tied to a wallet created specifically to receive any returned funds.

Supra's designated return address: 0x913BDd807608DEA920C689a7c3222E94e07551cC

Whether that address ever receives anything is separate from the question of whether the offer will work at all. A standing bounty is not recovered money, and as of publication, the $9.05 million principal — including the amount Wallet B pledged to return — remains unrecovered.

04Audited, but not the part that mattered

Bonzo's core lending infrastructure had gone through conventional security review. Halborn's audits cover the lending contracts, liquidity incentives, staking module, LayerZero bridge connector, and vaults — and none of that work implicates Bonzo's own code in this incident. The protocol's documentation also lists Chainlink and Supra as its two oracle providers, but SAUCE and wHBAR pricing depended on Supra exclusivelyChainlink's coverage extends to HBAR and USDC, not the pair that was actually exploited. Having a second oracle provider offers little protection when the affected asset pair was never dual-sourced.

Bonzo does maintain a bug bounty scope, and it explicitly excludes exactly this kind of dependency: the program covers lending contracts, vaults, and the staking module, while stating plainly that "third-party contracts not directly associated with Bonzo Finance" are out of scope. Supra's verifier falls squarely into that excluded category — a contract Bonzo relies on but never controlled, meaning no one would have been compensated for flagging a bug in it under Bonzo's own policy.

Supra's audit history is arguably even thinner. The only publicly available audit of Supra's oracle work is a MoveBit report written years before this exploit, scoped to Supra's Aptos contracts written in Move — an entirely different chain and language. The Hedera-specific verifier component, requireHashVerified_V2, that actually failed does not appear anywhere in that report — it wasn't excluded; it was simply never covered in the first place.

Tobkin's claim that the bug went unnoticed for two years becomes more credible once you consider there's no evidence any external reviewer ever examined that specific code path. Tobkin himself framed the situation through a memorable analogy: being a DeFi founder can feel like the classic nightmare of showing up to school naked, and this exploit made that literal — "we're all naked in the hallway now," he wrote. Later in the same message, almost as an aside, he noted that Supra had "recently started" formal verification work on its systems, calling the timing "ironic" given what had just occurred. In short: Bonzo had deliberately carved this dependency out of its bounty program, and Supra, by its own CEO's admission, had not yet subjected it to formal verification.

05Closing thought

A zero-value signature satisfying a zero-value public key is the entire technical story behind a $9.05 million loss. The verifier trusted a mathematically correct answer to a question it should never have allowed to be asked. Three safeguards — now implemented — would have prevented the exploit had they existed beforehand; instead, the gap persisted for two years, unnoticed by human reviewers, until something faster than human review, by Supra's own CEO's account, finally caught it.

The stolen funds moved across three chains and through a mixer before investigators could tie any wallet to an identity, and a bounty offer currently stands in place of an actual recovery. Bonzo's own contracts passed every audit applied to them — irrelevant in the end, since the failure lay in a false input, not in the logic that processed it. Any protocol still depending on someone else's unaudited verifier is, knowingly or not, wagering that its own two-year-old blind spot hasn't yet been discovered.

Bonzo FinanceSignature Verification Bypass
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.