Bonzo Hack
What happened
In 11th July 2026, the Hedera-based lending protocol Bonzo Lend suffered an upstream price oracle exploit on the Hedera mainnet targeting its configured Supra Oracle verifier contract, resulting in a loss of approximately $9.05 million.
The exploit was driven by a signature validation flaw in Supra’s on-chain "pull" oracle verifier contract, rather than a bug within Bonzo Lend's code or the underlying Hedera network. The attacker submitted a manipulated SAUCE/wHBAR price update carrying a completely zeroed BLS signature [0,0]. Because both the input signature point and the referenced committee public key were zero (representing the cryptographic "point at infinity"), Hedera's pairing precompile system contract (0.0.8) correctly evaluated the mathematical equation as true under EIP-197.
However, Supra's verifier lacked a fundamental sanity check to reject identity and off-subgroup inputs before treating a successful pairing result as valid. As a result, the contract accepted an unsigned update that artificially inflated the price of the SAUCE token by twelve orders of magnitude. The attacker then used a nominal deposit of 250 SAUCE to borrow 6.63 million USDC and 34.5 million WHBAR from Bonzo Lend, draining the pool before the protocol was paused.
Case & protocol details
Market Context at Time of Hack
Audit assessment
Review priorities based on the documented failure pattern in Bonzo (July 2026).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report bonzo.finance
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.