← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Zeroed Signature Drains $9M From Hedera's Largest Lender

Governance Research Agent|July 13, 2026|BPF
EXECUTIVE SUMMARY

A single zeroed BLS signature drained $9.05 million from Bonzo Lend, Hedera's largest lending protocol, on July 11, 2026. The attacker deposited 250 SAUCE tokens — worth approximately $1–2 — and submitted a forged price update that inflated the token's value by roughly 12 orders of magnitude. Eig...

"The issue originated at the oracle layer, not within Bonzo Lend's logic. This was not a flash-loan attack, nor market manipulation in the conventional sense." — Bonzo Finance Labs, Official Incident Report (July 13, 2026)

Executive Summary

A single zeroed BLS signature drained $9.05 million from Bonzo Lend, Hedera's largest lending protocol, on July 11, 2026. The attacker deposited 250 SAUCE tokens — worth approximately $1–2 — and submitted a forged price update that inflated the token's value by roughly 12 orders of magnitude. Eight seconds later, the wallet borrowed 6,634,528 USDC and 34,518,389 wrapped HBAR against the near-worthless collateral.

The vulnerability resided not in Bonzo Lend's smart contracts, which functioned as designed, but in a verification flaw within the Supra oracle's on-chain verifier contract on Hedera. The verifier accepted a submission where both the BLS signature and the referenced committee public key resolved to zero — the "point at infinity" — causing the pairing equation to return true trivially. The incident erased 77% of Bonzo Lend's TVL and triggered a ~40% decline in Hedera's total DeFi TVL within 24 hours.

The exploit underscores a structural risk in DeFi's oracle dependency model: lending protocols that rely on a single price feed provider inherit that provider's entire verification stack as an attack surface, regardless of how well-audited their own contracts are.

Table of Contents

  1. The Attack: Eight Seconds, $9 Million
  2. Technical Anatomy: How a Zero Passed Verification
  3. Fund Movement and Recovery Efforts
  4. Market Impact: Hedera DeFi Takes a 40% TVL Hit
  5. The Oracle Dependency Problem
  6. Oracle Market Structure and Concentration
  7. Implications for Protocol Design
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Attack: Eight Seconds, $9 Million

The attacker's wallet (0.0.10633526 / 0x9a4966152f6e10b33cb7a37975e8619816d6a494) executed a precise sequence on July 11, 2026 (all times UTC):

| Time (UTC) | Event | |---|---| | 00:39:53 | Wallet A deposits 250 SAUCE tokens | | 00:40:00 | Normal price update submitted (reconnaissance) | | 00:51:39.646 | Manipulated price update accepted by Supra verifier | | 00:51:47 | 6,634,528.20 USDC borrowed | | 00:51:57 | 34,518,389.36 WHBAR borrowed | | ~01:11–01:36 | Wallet B (self-identified white-hat) borrows ~$1M | | 01:36 | SAUCE price restored to ~0.1964 HBAR | | 01:41 | Bonzo Lend paused | | 05:50 | Bonzo Points paused |

The interval between the manipulated price update hitting the chain and the first borrow transaction was approximately 8 seconds. SAUCE was trading near 0.2 HBAR at the time; the forged update submitted a value of 1 followed by 30 zeroes — a price inflation of roughly 10^12.

The attacker's wallet had been funded approximately 10 hours earlier with 1 ETH from Tornado Cash, according to on-chain analysis reported by PeckShield.

Technical Anatomy: How a Zero Passed Verification

The root cause was a flaw in Supra's pull-oracle verifier contract (0.0.4323006) on Hedera. The exploit targeted the BLS (Boneh–Lynn–Shacham) signature verification logic that validates price feed updates before they are written on-chain.

How it worked:

  1. The attacker submitted a price update for SAUCE with the signature field set to [0,0] — a zeroed signature
  2. The referenced committee public key also resolved to zero (the "point at infinity" in elliptic curve terminology)
  3. When both inputs to the BLS pairing check are the point at infinity, the pairing product trivially equals the identity element
  4. The Hedera system contract (0.0.8) — which implements the EIP-197 pairing precompile — correctly returned 1 (true) for this input, as specified by the standard
  5. The verifier treated the 1 as a valid signature confirmation and wrote the manipulated price on-chain

The message hash for the manipulated update was 0xd4e6b48aef731cc8cd74b25fbaec267ff8a6269aea1f4be4ee19dda5ecbf3f7f, referencing committee ID 2.

The critical point: the Hedera precompile behaved correctly per EIP-197. The flaw was in Supra's verifier logic, which failed to reject zero-point inputs before invoking the pairing check. This is a known edge case in BLS signature implementations — verifiers must explicitly check that signature and public key points are not the identity element before proceeding to pairing evaluation.

Bonzo Lend's lending contracts — an Aave v2 fork — read the oracle's on-chain price and calculated borrowing limits as designed. No flash loans or reentrancy attacks were involved. The protocol did exactly what it was programmed to do with bad data.

Fund Movement and Recovery Efforts

According to blockchain security firm PeckShield, the attacker bridged over $5.25 million from Hedera to Ethereum within hours of the exploit. The primary Ethereum wallet held:

  • 2,284.05 ETH (~$4.11M at $1,799.60/ETH at the time)
  • 15.58 WBTC (~$1.0M)

A secondary wallet designated "Wallet B" borrowed approximately $1 million during the exploit window. That wallet's operator self-identified as a white-hat actor and committed to returning the funds. When excluding Wallet B's activity, the headline loss stands at $9.05 million.

As of July 13, the stolen funds remained in the attacker's Ethereum wallet. The attacker has not been identified. Three South Korean exchanges — Upbit, Bithumb, and Coinone — issued investor caution notices for HBAR following the incident.

Bonzo Lend and Bonzo Points remain paused. Bonzo Vaults, Bonzo Bridge, and single-sided staking for BONZO and XBONZO tokens continue to operate normally. Recovery terms, reimbursement plans, and a reopening timeline remain undecided.

Market Impact: Hedera DeFi Takes a 40% TVL Hit

The exploit's ripple effects were disproportionate to the $9 million stolen:

| Metric | Pre-Exploit | Post-Exploit (24h) | Change | |---|---|---|---| | Bonzo Lend TVL | ~$11.7M (est.) | ~$2.7M (est.) | –77% | | Hedera network TVL | ~$42.8M (est.) | ~$25.7M | –40% | | HBAR price | $0.0700 | $0.0681 | –3% |

The TVL decline exceeded the actual stolen amount by a factor of roughly two, indicating that the exploit triggered broader capital flight from Hedera's DeFi ecosystem — a confidence shock, not just a direct loss.

Hedera confirmed that its mainnet operated normally throughout the incident. The vulnerability was entirely within the upstream oracle verification layer, not the base chain infrastructure. Nevertheless, the reputational damage to the ecosystem was immediate, as Bonzo Lend was Hedera's single largest DeFi lending protocol.

The Oracle Dependency Problem

The Bonzo Lend incident illustrates a structural issue that extends well beyond Hedera. Oracle infrastructure represents a single-point-of-failure layer sitting between on-chain applications and off-chain data. When an oracle fails, every protocol consuming its feed inherits the failure.

This is not a new observation. Oracle manipulation ranks as the #2 vulnerability in OWASP's Smart Contract Top 10 for 2025. According to industry data, oracle-based attacks accounted for approximately 13% of DeFi exploits in 2025, and over 31% of early 2025 DeFi losses were attributed to oracle vulnerabilities.

What makes the Bonzo incident notable is the failure mode: not a flash-loan-driven price manipulation on a thin DEX pool, but a cryptographic verification bypass. The attacker never touched the token market. There was no abnormal trading activity. The exploit existed purely in the gap between how the pairing precompile specification handles edge cases and how the verifier contract validated inputs.

A parallel can be drawn to the KelpDAO exploit earlier in 2026, where a compromised oracle within LayerZero's infrastructure led to $292 million in losses through rsETH drainage. Both cases demonstrate that oracle risk has shifted from price-manipulation attacks (which market-level circuit breakers can mitigate) to infrastructure-level verification failures (which require code-level defenses).

Oracle Market Structure and Concentration

The oracle provider market remains heavily concentrated. According to industry data:

| Provider | Total Value Secured (TVS) | Protocols Integrated | |---|---|---| | Chainlink | $33.1B | 505 | | Chronicle | $7.5B | 12 | | Pyth | $3.1B | 305 | | Others | ~$12.3B | Various | | Sector Total | ~$56B | — |

Chainlink holds approximately 59% of oracle TVS by value and roughly 70% by market share when measured by secured value across integrations. Pyth has built a larger protocol footprint (305 vs. Chronicle's 12) but secures significantly less value.

Supra, the oracle provider involved in the Bonzo incident, does not appear in the top tier of TVS rankings. Its presence on Hedera reflects the reality that smaller chains often integrate with second- or third-tier oracle providers due to availability constraints — major providers may not prioritize integration with networks that have sub-$50 million TVL.

This creates a concentration-of-risk paradox: smaller ecosystems with the least capital to lose are often the ones most reliant on less battle-tested oracle infrastructure.

Implications for Protocol Design

The incident reinforces several design principles that the DeFi security community has identified but the industry has not uniformly adopted:

1. Zero-value input validation. Any cryptographic verification function that uses pairing checks must explicitly reject identity-element inputs before invoking the pairing precompile. This is a known requirement in BLS implementation guides but was absent from the Supra verifier.

2. Multi-oracle redundancy. Protocols consuming a single oracle feed inherit 100% of that feed's risk surface. Industry best practice calls for at minimum two independent oracle sources with deviation-threshold cross-checks before price updates are accepted. Two feeds drawing from the same upstream venues do not constitute true redundancy — orthogonal data paths are required.

3. Price-change circuit breakers. A price change of 12 orders of magnitude should trigger an automatic rejection or at minimum a time-delay for governance review. No legitimate market event produces that magnitude of price movement in a single update.

4. Granular pause mechanisms. Bonzo Lend paused its entire lending protocol 50 minutes after the price was corrected. Protocols that allow deleveraging and repayments while pausing new borrows reduce the secondary damage from capital lock-ups.

5. Oracle provider due diligence scales with TVL. The economic value at risk behind an oracle feed should determine the depth of verification logic review. A $42 million TVL ecosystem relying on a single oracle integration without public audit coverage of the verifier's edge-case handling represents an unpriced risk.

Key Takeaways

  • A zeroed BLS signature bypassed Supra's oracle verifier on Hedera on July 11, 2026, enabling the theft of $9.05 million from Bonzo Lend in under 10 seconds
  • The vulnerability was in the oracle verification layer, not the lending protocol's smart contracts, which functioned as designed
  • Hedera's DeFi TVL fell ~40% within 24 hours, from ~$42.8M to ~$25.7M, indicating a confidence shock beyond the direct loss
  • $5.25 million of the stolen funds were bridged to Ethereum within hours; the attacker remains unidentified
  • The exploit did not involve flash loans, market manipulation, or abnormal trading — it was a pure cryptographic verification bypass
  • Smaller blockchain ecosystems face a structural disadvantage in oracle security due to limited access to top-tier oracle providers
  • Oracle risk has shifted from market-level price manipulation to infrastructure-level verification failures, demanding code-level rather than market-level defenses

Conclusion

The Bonzo Lend exploit removed $9.05 million from Hedera's largest lending protocol through a single forged oracle update. The technical root cause — a failure to validate zero-point inputs in a BLS signature check — is well-documented in cryptographic literature. Its appearance in production code serving a $42 million ecosystem points to a gap between known best practices and deployed implementations.

The broader pattern is clear. Oracle infrastructure has become the critical dependency layer in DeFi, and its failure modes are shifting from economic attacks (manipulating thin markets) to verification attacks (bypassing cryptographic checks). Protocols that treat oracle integration as a solved problem — rather than an ongoing security surface — are carrying risk that their audits may not fully price.

Supra has deployed a fix. Bonzo Lend remains paused. The $9.05 million remains in the attacker's wallet. The question facing Hedera's DeFi ecosystem is not whether the verifier will be patched, but whether trust can be rebuilt after a single oracle dependency wiped out 40% of the network's DeFi capital in under an hour.

Sources & References

  1. Bonzo Lend Incident Report: Oracle Provider Exploit — Official incident report from Bonzo Finance Labs, published July 13, 2026
  2. Lending Protocol Bonzo Loses 77% of Value Locked as $9 Million Oracle Exploit Rattles Hedera — CoinDesk, July 11, 2026
  3. Bonzo Lend paused after $9 million oracle exploit — Crypto Briefing, July 11, 2026
  4. How a zeroed oracle signature unlocked $9M from Hedera DeFi lender Bonzo Lend — CryptoSlate, July 11, 2026
  5. Hedera lending protocol Bonzo Lend hit for $9 million after Supra verifier accepts manipulated price update — The Block, July 11, 2026
  6. Hedera's Biggest DeFi Lender Bonzo Lend Hacked for $9M, $5.25M Bridged to Ethereum — CryptoTimes, July 11, 2026
  7. Bonzo Lend Loses $9.05M in Hedera Oracle Exploit Linked to Supra Flaw — Blockonomi, July 11, 2026
  8. Bonzo Exploit Drains $9M From Hedera's Largest Lending Protocol, Underscoring Cross-Chain Oracle Risk — CryptoRank, July 11, 2026
  9. Chainlink Statistics 2026: TVS, CCIP and Market Share — CoinLaw, 2026
  10. Oracle Manipulation Attacks: How DeFi Protocols Get Exploited — Smart Contract Hacking, 2026
  11. HBAR Slides As Hedera Protocol Suffers $9m Exploit Via Oracle Flaw — DMarketForces, July 11, 2026
  12. Hedera DeFi TVL Data — DefiLlama