A single unrejected zero-signature in a third-party oracle drained $9.05M from Hedera's largest lender in eight seconds β and six days later the Hedera Foundation committed to making every user whole, a rare full-backstop precedent for the industry.
$9.05 million was extracted from Bonzo Lend on July 11, 2026 in an eight-second attack window (00:51:39β00:51:57 UTC), crashing Bonzo's TVL by 77% and Hedera network-wide TVL by nearly 40% in 24 hours, down to roughly $25.7 million.
The root cause was not a Bonzo smart contract bug but a third-party Supra oracle verifier flaw: a submission with a zeroed BLS signature and zeroed public key passed Hedera's pairing precompile because the identity-point pairing trivially returns "true," and Supra's contract wrongly treated that as a valid committee signature.
On July 17, 2026, the Hedera Foundation committed a recovery facility to restore all affected users to their exact pre-exploit position value, administered as a separate advance program outside the paused protocol's smart contracts β one of the most direct full-backstop commitments a layer-1 foundation has made for a third-party dApp exploit.
Roughly $5.25 million of the stolen funds was bridged via LayerZero to Ethereum within hours and consolidated into ~2,284 ETH and ~15.58 WBTC, with the attacker's funding wallet traced to a Tornado Cash deposit ~10 hours pre-exploit β recovery of bridged funds is not guaranteed and the Foundation's facility effectively substitutes for asset recovery.
Bonzo Lend markets remain paused while new redemption contracts undergo Halborn audits, with "no rushed timeline" β the next catalyst is the follow-up blog post detailing eligibility and disbursement mechanics, expected to determine whether user trust and Hedera DeFi TVL actually recover.
Bonzo Finance (branded in-app as Bonzo Lend) is Hedera's largest non-custodial lending and borrowing protocol, built to let users supply and borrow HBAR, Hedera Token Service (HTS) assets like SAUCE, and wrapped majors such as Wrapped HBAR (WHBAR) and bridged USDC. As an Aave-style money market adapted for Hedera's hashgraph consensus and native tokenization layer, Bonzo has functioned as the primary liquidity backbone for the network's broader DeFi stack, sitting alongside SaucerSwap (the dominant Hedera DEX, which grew TVL 70.1% quarter-over-quarter to $77.6 million as of Q3 2025) as one of the two pillars of Hedera DeFi.
The exploit lands at a fragile moment for Hedera. HBAR was already trading near $0.067β$0.070 in mid-July 2026, roughly 81% below its all-time high, with commentary pointing to weak fee revenue generation relative to other L1s even as the network pursued institutional narratives β including a widely covered deepening of Lloyds Banking Group's involvement with Hedera-based infrastructure around the same week. Hedera's DeFi ecosystem had been in a genuine growth phase heading into 2026, with total DeFi TVL up 53.4% quarter-over-quarter to $113.5 million as of Q3 2025. The Bonzo exploit erased a large share of that momentum overnight, pulling network-wide TVL down toward $25.7 million and reviving longstanding questions about whether Hedera's DeFi layer can scale safely alongside its enterprise and institutional pitch.
The broader significance of this event extends well past Hedera. Oracle infrastructure is shared, cross-chain plumbing β Supra, the oracle provider implicated here, services price feeds across multiple ecosystems, not just Hedera. A verifier-logic flaw of this type (accepting a degenerate/zero-value cryptographic signature as valid) is a class of bug that has recurred across the industry in various forms, and it strikes at a layer that individual protocols like Bonzo have little direct control over: they consume oracle prices as ground truth and have limited ability to independently audit or override third-party feed infrastructure in real time. That dependency is precisely why the loss happened in eight seconds and why any fix has to happen at the oracle layer, not just the lending-protocol layer.
Finally, the Hedera Foundation's response is itself a market-structure event worth studying independent of the technical postmortem. Full backstops for third-party dApp exploits are uncommon; foundations more typically offer partial insurance funds, negotiate with attackers, or leave users to recovery via legal process or DAO governance votes. A layer-1 foundation stepping in to guarantee dollar-for-dollar restoration of pre-exploit position value β funded outside the protocol's own paused contracts β sets a precedent other ecosystems (and other Hedera dApps in future incidents) will be measured against.
July 11, 2026, 00:51:39 UTC β Attacker wallet ("Wallet A," Hedera account 0.0.10633526 / EVM alias 0x9a4966152f6e10b33cb7a37975e8619816d6a494) submits a fraudulent SAUCE price update to Supra's oracle contract on Hedera mainnet. The submission carries committee ID 2, a zeroed BLS signature [0,0], and a message hash of 0xd4e6b48aef731cc8cd74b25fbaec267ff8a6269aea1f4be4ee19dda5ecbf3f7f. Supra's verifier fails to reject the zero/identity inputs before invoking Hedera's BLS pairing precompile (contract 0.0.8); because both the signature and public key are the identity point, the pairing product is trivially "true," and the contract wrongly accepts it as a legitimate committee-signed price. SAUCE's HBAR-denominated price is inflated from roughly 0.2 HBAR to a number on the order of 10^30 β approximately twelve orders of magnitude above true value.
July 11, 2026, 00:51:47β00:51:57 UTC β Eight seconds after the price manipulation lands, the same wallet deposits just 250 SAUCE tokens (worth a few dollars at fair value) as collateral and, against the fraudulently inflated valuation, borrows 6,634,528.20 USDC and 34,518,389.36 WHBAR β roughly $9.05 million combined.
July 11, 2026 (same day, within hours) β A second wallet ("Wallet B," Hedera 0.0.683607) exploits the same still-live manipulated price to borrow an additional $1 million before Bonzo's team catches and pauses the pool. This wallet later contacts Bonzo via Discord, self-identifies as a white-hat actor, and states intent to return the funds β Bonzo subsequently excludes this amount from its headline $9.05M loss figure. Separately, security analysts (initially flagging via researcher "Specter," later corroborated by PeckShield) observe roughly $5.25 million of the stolen funds bridged from Hedera to Ethereum using LayerZero, consolidating into two Ethereum addresses (0x9A4966152F6e10b33Cb7a37975e8619816d6a494 and 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e) holding approximately 2,284.05 ETH ($4.11M) and 15.58 WBTC (~$1M). The attacker's funding wallet is traced to a 1 ETH deposit from Tornado Cash roughly 10 hours before the exploit, a signature consistent with pre-planned, non-opportunistic execution.
July 11, 2026, 01:36 UTC β Legitimate oracle publishing restores SAUCE's price to approximately 0.1964 HBAR, just five minutes before Bonzo pauses its lending markets entirely to halt further exploitation.
July 11β13, 2026 β Bonzo publishes and then updates its incident report (initial post 6:06 p.m. July 11, updated 8:12 a.m. July 13), confirming the exploit was isolated to Supra's oracle verifier rather than any flaw in Bonzo's own lending contracts. Supra Labs separately publishes its own postmortem, attributing the failure to a degenerate BLS signature and zero-valued public key wrongly accepted for a single SAUCE/wHBAR feed, and states its core aggregation logic and other price feeds were unaffected. Supra deploys a patched verifier contract to Hedera mainnet.
July 17, 2026 β The Hedera Foundation announces it will back a recovery facility enabling Bonzo to restore all affected users to their exact pre-exploit position values. Advances are distributed through a dedicated program administered separately from Bonzo's (still-paused) smart contracts, following a verification step before disbursement. The Foundation states funding "is designated solely for recouping individual user losses and will not be used for any other purpose," and that "security is the priority and no rushed timeline has been set" β tying full relaunch to completion of Halborn's audit of new redemption contracts. Users are told no action is required at that time, with full eligibility and claims details to follow in a subsequent post.

The exploit is a textbook example of a verifier-boundary failure rather than a cryptographic break of BLS signatures themselves. BLS (BonehβLynnβShacham) signatures rely on bilinear pairings: a verifier checks that e(signature, G2) = e(H(message), publicKey) using a pairing function e. The mathematical property that made this exploitable is that the pairing of two identity-point (zero) inputs is itself trivially the identity element β meaning e(0, 0) evaluates as a valid-looking equality, satisfying a naive pairing check even though no actual signing operation occurred. A correctly implemented verifier must explicitly reject zero/identity-point signatures and public keys before ever invoking the pairing check, precisely because the check cannot distinguish "a real committee signed this" from "nobody signed this and both inputs are null." Supra's Hedera verifier skipped that pre-check, passed the zeroed inputs straight into Hedera's native BLS pairing precompile (contract 0.0.8), received a "true" result, and treated that as cryptographic proof of committee authorization for a price it never actually approved.
This is architecturally significant because it demonstrates how a single missing input-validation line in a shared oracle contract can cascade into a nine-figure-adjacent loss for a downstream consumer that had no visibility into or control over the flaw. Bonzo's own lending logic β collateralization ratios, liquidation thresholds, interest accrual β functioned exactly as designed throughout the attack; the protocol correctly extended loans against collateral it was told, by an trusted external price feed, was worth far more than it was. This is the same fundamental class of risk that has recurred across DeFi's history (flash-loan price manipulation, stale-oracle exploits, single-source feed attacks), but here the twist is that it wasn't a manipulable market price (like a thin-liquidity DEX pool) being gamed β it was the cryptographic attestation layer meant to guarantee the price's authenticity that failed outright.
The speed of exploitation β eight seconds from manipulated price landing to loan extraction β underscores why oracle security cannot rely on human-reaction-time circuit breakers alone; Bonzo's team paused the pool only after the damage was done, restoring legitimate pricing five minutes after (but crucially only minutes before) the pause. Effective defenses against this class of attack generally require on-chain, automatic guardrails: price-deviation caps that reject updates moving a feed value by implausible multiples in a single block, minimum time-weighted averaging before a new price is actionable for borrowing, and defense-in-depth verifier logic that treats degenerate cryptographic inputs (zero, identity, malformed curve points) as automatic rejects rather than edge cases that happen to pass a check. Supra's patched verifier reportedly now enforces the missing zero-signature rejection Bonzo's incident report says should have existed from the start.
The recovery architecture is itself worth examining as a design decision. Rather than attempting an in-place contract upgrade or a governance-voted socialized-loss mechanism (common in past DeFi exploits), Bonzo and the Hedera Foundation chose to (1) keep the exploited pool fully paused, (2) build and independently audit new redemption contracts via Halborn rather than patching the compromised ones in place, and (3) fund user restitution through a separate advance program disconnected from the vulnerable contract entirely. This sequencing prioritizes provable safety over speed β an explicit tradeoff the Foundation flagged when it said "no rushed timeline has been set."
sequenceDiagram
participant Attacker as Attacker Wallet A
participant Supra as Supra Oracle Verifier
participant Precompile as Hedera BLS Precompile (0.0.8)
participant Bonzo as Bonzo Lend Pool
participant WhiteHat as Wallet B (White-hat)
participant Bridge as LayerZero Bridge
participant Foundation as Hedera Foundation
Attacker->>Supra: Submit fake SAUCE price (zeroed [0,0] signature)
Supra->>Precompile: Pass unvalidated zero inputs to pairing check
Precompile-->>Supra: Returns "true" (identity pairing trivially valid)
Supra->>Bonzo: Accept price as legitimate (SAUCE inflated ~10^12x)
Attacker->>Bonzo: Deposit 250 SAUCE, borrow $9.05M (USDC + WHBAR)
WhiteHat->>Bonzo: Exploit same window, borrow ~$1M
Attacker->>Bridge: Bridge ~$5.25M to Ethereum via LayerZero
Bonzo->>Bonzo: Detect anomaly, pause lending markets
Note over Bonzo,Supra: Legitimate price restored 5 min before pause
Supra->>Supra: Deploy patched verifier (rejects zero signatures)
Foundation->>Bonzo: Commit recovery facility (July 17)
Foundation->>Foundation: Restore all users to pre-exploit position valueMetric | Value | Change | Source |
|---|---|---|---|
Bonzo exploit loss (confirmed) | $9.05 million | β | |
Bonzo Finance TVL | $14.3 million (post-exploit) | β77% | |
Hedera network-wide TVL | ~$25.7 million | β~40% in 24h | |
Funds bridged to Ethereum (LayerZero) | ~$5.25 million | ~$3.7M β $5.25M within hours | |
HBAR spot price (mid-July 2026) | ~$0.067β$0.070 | ~β81% from ATH | |
Attacker consolidated holdings | ~2,284.05 ETH + 15.58 WBTC | ~$4.11M + ~$1M | |
Hedera DeFi TVL (pre-incident, Q3 2025 baseline) | $113.5 million | +53.4% QoQ |
The data tells a story of concentration risk compounding technical risk. Bonzo alone accounted for a large enough share of Hedera's total DeFi liquidity that its 77% TVL collapse translated directly into a network-wide 40% TVL drawdown β an unusually high correlation that reflects how thin and concentrated the Hedera DeFi stack still is relative to more mature L1 ecosystems, where a single protocol's failure rarely moves aggregate network TVL by double digits. The gap between the $9.05M attacker loss and the $5.25M actually bridged off-chain also matters: it suggests a meaningful portion of stolen value (over $4M) may still be traceable or recoverable on Hedera-native rails or in transit, even as the Ethereum-side funds sit in wallets funded via Tornado Cash β a strong signal of premeditation and a strong signal that direct on-chain recovery of the bridged portion is unlikely, reinforcing why the Hedera Foundation chose to fund restitution directly rather than wait on asset clawback.
The HBAR price reaction β a relatively contained ~2%+ dip rather than a double-digit crash β is notable against a 77%/40% TVL collapse; it suggests markets read the exploit as isolated to a third-party oracle and idiosyncratic to Bonzo rather than as an indictment of Hedera's base-layer consensus (hashgraph) or native token economics, consistent with Bonzo's own framing that its lending contracts performed exactly as designed. That relative price resilience may also be what gave the Hedera Foundation room to commit capital to a full backstop without triggering a deeper confidence crisis in HBAR itself.

SaucerSwap (Hedera DEX) remains the dominant protocol on Hedera by TVL ($77.6M as of Q3 2025, over two-thirds of network DeFi liquidity), and unlike Bonzo, its core function (automated market-making) doesn't depend on external price oracles for solvency in the same acute way lending does β AMM pools are self-pricing via reserves, making SaucerSwap structurally less exposed to this specific class of oracle-verifier exploit, though it remains exposed to oracle risk wherever it integrates external price feeds for auxiliary features.
HLiquity, a newer Hedera lending entrant, offers interest-free HBAR-collateralized loans disbursed in HCHF (a Swiss-Franc-pegged stablecoin), modeled on Liquity's immutable, governance-minimized architecture on Ethereum. Its narrower asset scope (HBAR collateral only, single stablecoin output) reduces the oracle attack surface relative to Bonzo's broader multi-asset money market, though it sacrifices the flexibility that made Bonzo the network's largest lender.
Aave and Compound (multi-chain incumbents) represent the standard Bonzo was explicitly modeled after, but both have iterated through years of oracle-security hardening β including Chainlink's deeply battle-tested decentralized oracle network, circuit breakers, and multiple historical incident responses β that a newer, smaller-ecosystem protocol like Bonzo, dependent on a comparatively less battle-tested oracle provider (Supra), had not yet accumulated. This exploit is a reminder that oracle maturity, not just lending-contract maturity, is a key differentiator between "established DeFi" and "emerging L1 DeFi."
Other Supra-integrated protocols across chains face latent exposure to the same verifier class of bug, even though Supra says its core aggregation logic and other feeds were unaffected and the flaw was isolated to the single SAUCE/wHBAR feed's Hedera verifier. Any protocol relying on Supra's Hedera integration β or structurally similar BLS-based oracle verifiers elsewhere β should treat this as a prompt to audit their own oracle dependency for identical zero-signature/identity-point validation gaps, since the underlying pairing-math edge case is not Hedera-specific.
Bonzo users/depositors are, on net, the biggest beneficiaries of the Foundation's intervention: a full pre-exploit restoration is a materially better outcome than the socialized haircuts, governance-token compensation schemes, or protracted legal recovery processes that have characterized most historical DeFi exploits. The tradeoff is time β funds remain locked with "no rushed timeline," and until the follow-up eligibility post lands, individual users don't yet know the precise mechanics or timing of their own claim.
HBAR/Hedera Foundation faces a direct financial cost (the recovery facility's size wasn't disclosed at time of writing) but gains a reputational asset: demonstrating that Hedera's ecosystem stewardship extends to backstopping third-party dApp failures, not just its own protocol layer. This is a deliberate trust-rebuilding move at a moment when HBAR price and DeFi TVL were both already under pressure, and it directly counters the narrative risk that a major hack drives users permanently off the network.
Bonzo Labs/Bonzo Finance Foundation absorbs the operational and audit burden β coordinating Halborn's review of entirely new redemption contracts β while its market position as "Hedera's largest lending protocol" is now conditional on successfully relaunching without a repeat incident. A botched or excessively delayed relaunch risks ceding share to HLiquity or new entrants even if user funds are ultimately made whole.
Supra Oracle bears the direct technical blame and reputational hit as the root-cause vendor, but its rapid patch deployment and transparent incident report (isolating the flaw to a single feed's verifier rather than core aggregation) is a mitigating factor for its broader multi-chain client base, who need reassurance the flaw was narrowly scoped rather than systemic.
Regulators and institutional observers β relevant given Hedera's simultaneous institutional push (e.g., the Lloyds Banking Group coverage running concurrently) β will likely view the Foundation's willingness to fully backstop retail losses favorably from a consumer-protection standpoint, even as the exploit itself reinforces skepticism about DeFi's operational risk that has historically slowed institutional DeFi adoption.
Bridged-fund non-recovery β The ~$5.25 million already moved to Ethereum via LayerZero and consolidated into ETH/WBTC, funded from a Tornado Cash-linked wallet, is unlikely to be clawed back through on-chain means alone. Severity: high (direct financial loss to the ecosystem/Foundation, which must effectively self-fund the shortfall). Probability: near-certain that at least a substantial portion remains unrecovered absent law-enforcement action.
Recovery facility execution risk β The Foundation has committed to restoration but disclosed no funding amount, no firm timeline, and no finalized eligibility criteria as of July 17. Any gap between promise and delivery (partial payouts, disputed eligibility, further delay) could convert a reputational win into a renewed trust crisis. Severity: medium-high. Probability: moderate, given the explicit "no rushed timeline" framing already signals execution complexity.
Recurrence via the same oracle-verifier class of bug β Supra's patch addresses the specific zero-signature gap on the affected feed, but the underlying pattern (missing degenerate-input validation before a cryptographic pairing check) may exist in other Supra feeds, other Hedera oracle integrations, or entirely different BLS-based verifiers elsewhere in the industry. Severity: high if recurrence happens on Hedera again so soon after this incident. Probability: low-to-moderate in the near term given heightened scrutiny, but non-zero across the broader multi-chain Supra deployment.
Prolonged relaunch depressing Hedera DeFi TVL and HBAR sentiment β With Bonzo Lend markets paused indefinitely pending Halborn audit completion, Hedera's DeFi liquidity (already down to ~$25.7M network-wide) may struggle to recover if the largest lender remains offline for an extended period, compounding pressure on an HBAR price already near multi-year lows. Severity: medium. Probability: moderate, contingent entirely on how quickly the new redemption contracts clear audit.

For funds and treasuries with exposure to Hedera DeFi, the near-term calculus hinges on the Foundation's follow-up disclosure: until eligibility criteria, funding size, and disbursement timing are public, position-sizing decisions around HBAR, SAUCE, or Bonzo-adjacent exposure should assume continued uncertainty rather than price the recovery as a done deal. That said, the Foundation's explicit, publicly stated commitment to full pre-exploit restoration is a meaningfully de-risking signal relative to protocols that go silent or negotiate opaque partial settlements after a hack β funds evaluating Hedera-ecosystem risk going forward should weight this precedent as evidence of stronger-than-typical L1-foundation backstop culture, which may command a premium versus otherwise-comparable smaller-cap L1 DeFi ecosystems without similar track records.
For protocols building on Hedera or integrating Supra oracles elsewhere, the immediate actionable takeaway is a mandatory audit of any BLS (or other pairing-based) signature verification path for explicit rejection of zero/identity-point inputs prior to the pairing check itself β this is a narrow, specific, and cheap fix relative to the damage a missed instance can cause, and any protocol that cannot affirmatively confirm this check exists in its oracle dependencies should treat it as a priority-one finding. More broadly, teams building lending markets on any newer L1 should weight oracle-provider maturity (track record, audit history, feed redundancy, deviation-cap design) as heavily as they weight their own contract audits β this incident is proof that the lending contract can be flawless and the protocol still loses 77% of TVL through no fault of its own code.
For builders and ecosystem participants evaluating where to deploy on Hedera, the relaunch timeline and the specifics of the new Halborn-audited redemption contracts are the two concrete signals to watch before re-engaging with Bonzo specifically; the broader Hedera DeFi ecosystem's health is now a lagging indicator of how convincingly the Foundation's recovery program executes, given how much of network TVL still runs through a small number of protocols.
30 days: Bonzo publishes the promised follow-up post detailing exact eligibility criteria and claims mechanics for the recovery facility; expect the disclosed facility size to fall in the high-single-digit millions (roughly matching or slightly exceeding the $9.05M confirmed loss once the white-hat-returned ~$1M is netted out). Halborn's audit of the new redemption contracts remains in progress and is not yet complete.
180 days: Bonzo Lend relaunches on Hedera mainnet with redemption contracts live and the bulk of eligible users paid out; Hedera network-wide DeFi TVL partially recovers but likely remains below the pre-exploit ~$113.5M(ish) trajectory implied by Q3 2025 growth rates, as some users and liquidity permanently reallocate to SaucerSwap or off-Hedera venues. Supra's patched verifier logic is independently re-audited and possibly adopted as a template fix communicated to other Supra-integrated chains.
365 days: The Bonzo/Hedera Foundation full-backstop response becomes a referenced precedent in industry discussions of DeFi insurance and foundation responsibility, cited alongside (or contrasted with) other major protocol exploit responses; whether Hedera's DeFi TVL has structurally recovered by then depends less on this single incident and more on whether Hedera converts its concurrent institutional narrative (e.g., traditional-finance partnerships) into genuine on-chain liquidity growth that reduces the network's continued over-reliance on one or two dominant DeFi protocols.
Bonzo to Restore Pre-Exploit Positions with Hedera Backing β CryptoTimes
Bonzo Lend Incident Report: Oracle Provider Exploit β Bonzo Finance
Hedera's Biggest DeFi Lender Bonzo Lend Hacked for $9M, $5.25M Bridged to Ethereum β CryptoTimes
How a zeroed oracle signature unlocked $9M from Hedera DeFi lender Bonzo Lend β CryptoSlate
Bonzo Lend Loses $9.05M in Hedera Oracle Exploit Linked to Supra Flaw β Blockonomi
Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit β The Defiant
HBAR News Today: Hedera's TVL Falls 40% After $9.05M Bonzo Lend Exploit β CryptoRank
Hedera (HBAR) price forecast: Bonzo exploit, Lloyds adoption β Invezz
Hedera DeFi Lending Protocols - TVL, Fees, & Revenue β DefiLlama