← Radar

Incident case file

Sign in to watch

Bonzo Lend Oracle Manipulation — Supra BLS Signature Bypass

Incident date July 11, 2026

0 views

RecoveringHedera (cash-out bridged to Ethereum via LayerZerolaundered through Tornado Cash)Oracle manipulationCluster: BON-ORC-2026-07

Estimated loss

$9.1M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: Hedera Wallet A: 0x9A4966152F6e10b33Cb7a37975e8619816d6a494. Ethereum cash-out wallet: 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e (funded by Tornado.Cash 0.1 ETH ~10h pre-attack; portfolio snapshot post-swaps: ~2,284 ETH + 15.577 WBTC = ~$5.11M via Arkham).

Funds moved to: Attacker deposited 250 SAUCE (~a few dollars) as collateral, then borrowed 6.63M USDC + 34.52M wrapped HBAR (~$9.05M total). Funds bridged Hedera→Ethereum via LayerZero (~$5.25M tracked by @SpecterAnalyst). On Ethereum, ~20+ WBTC-to-ETH swaps executed via router 0x7f54f056...803a3be8a between 07:33-07:40 UTC on July 11. Cash-out finalized with Tornado Cash deposits confirmed by @SpecterAnalyst at 11:43 UTC. A second Wallet B (~$1M borrowed during the same window) identified itself as white hat
Attacker Hedera EOA 0x9A4966152F6e10b33Cb7a37975e8619816d6a494 (Wallet A). Ethereum cash-out EOA 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e (funded 1 ETH from Tornado.Cash 10h pre-attack). WBTC-to-ETH swap router 0x7f54f056...803a3be8a. Supra oracle verifier contract vulnerable on Hedera. Bonzo LendingPool proxy 0x236897c518996163E7b313aD21D1C9fCC7BA1afc (Hedera 0.0.7308459). Bonzo SupraOracle adapter 0xc0Bb4030b55093981700559a0B751DCf7Db03cBB (Hedera 0.0.7308480). White hat Wallet B (~$1M, unid

Timeline: ~4 days pre-attack (July 7): attacker Ethereum EOA funded 1 ETH from Tornado Cash. July 11, 2026 ~00:51:39 UTC (Hedera block): attacker deposits 250 SAUCE on Bonzo Lend, then submits a Supra oracle price update carrying a zeroed BLS signature. Both the signature point and the referenced public key resolve to zero, causing the BLS pairing check on the Hedera precompile to return true — the verifier accepts an invalid submission because a critical security check was not executed before the pairing step. SAUCE price is inflated ~12 orders of magnitude. +8 seconds: attacker borrows 6.63M USDC + 34.52M wHBAR against the artificially inflated collateral. ~01:36 UTC: legitimate SAUCE price restored to 0.1964 HBAR. ~01:41 UTC: Bonzo Lend paused. ~05:50 UTC: Bonzo Points paused. 07:33-07:40 UTC: ~20+ WBTC-to-ETH swap transactions executed on Ethereum. ~10:00 UTC: @SpecterAnalyst publicly identifies the exploit with the 2 theft addresses (over $3.7M already bridged). 11:43 UTC: Specter confirms the attack is linked to Bonzo Finance and tracks Tornado Cash deposits. Impact: Bonzo TVL -77%, Hedera network TVL -40% in 24h. Supra acknowledges the flaw and deploys a fix to the affected verifier contract. July 17, 2026: Bonzo Finance Foundation announces full user-position restoration equal to pre-exploit position value, backed by a facility committed by the Hedera Foundation. New redemption smart contracts to be audited by Halborn.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)