Bonzo Lend, a Hedera-based lending protocol, paused all withdrawals after an oracle verifier accepted a zero-signature proof, enabling a wallet to borrow $9.05 million against 250 SAUCE tokens.

The exploit occurred when Wallet A submitted a manipulated SAUCE/wHBAR price update at 00:51 UTC. Eight seconds later, the same wallet borrowed 6.63 million USDC, followed by a second borrow of 34.5 million wrapped HBAR. The attack inflated SAUCE’s token value by 12 orders of magnitude, even as the asset’s actual market price remained near 0.2 HBAR.

How the Vulnerability Worked

Supra, the oracle provider, sent zero-signature inputs to Hedera’s pairing precompile as part of the verification process. The signature field contained [0,0] and the public key pointed to the point at infinity. Hedera’s precompile returned true as designed for mathematical identity, but Supra’s verifier did not reject zero, identity, and off-subgroup inputs before treating the result as proof of a committee signature.

According to CryptoSlate’s analysis, “In plain English, the network answered the equation it received correctly, while the verifier mistook that answer for authorization.” Bonzo’s lending contracts then followed their programmed loan-to-value rules using the manipulated price stored by the oracle.

Recovery Status and Disputed Claims

Wallet B borrowed approximately $1 million and contacted Bonzo claiming white-hat responder status with intent to return funds. Bonzo counted ~$1 million as recovered, though the funds had not yet been returned at the time of reporting and the final recovery tally remained unsettled.

Bonzo Finance Labs and Bonzo Finance Foundation are determining the recovery path. Supra reported fixing the verifier. As of July 11, Bonzo posted a formal update stating the protocol remained paused. On July 13, both Bonzo Lend and Bonzo Points remained paused, with the status page listed as under maintenance. Liquidity providers remain locked out during the pause.

Frequently Asked Questions

How much was borrowed in the Bonzo Lend exploit?

A wallet borrowed $9.05 million against 250 SAUCE tokens after an oracle verifier accepted a zero-signature proof.

How did the oracle exploit work?

Supra, the oracle provider, sent zero-signature inputs whose signature field contained [0,0]; Hedera's precompile returned true, but Supra's verifier did not reject the identity inputs.

What is the recovery status?

Wallet B borrowed approximately $1 million and contacted Bonzo claiming white-hat status; Supra reported fixing the verifier, but on July 13 Bonzo Lend remained paused.