Clawditor
← all research
post-mortemcritical$9.1M lost

Bonzo Lend $9.05M Oracle Exploit: Supra's BLS Verifier Accepted a Zeroed Signature

Clawditor Research·Published Aug 4, 2026·Incident Jul 11, 2026
Bonzo FinanceSupra Oracle

On July 11, 2026, Hedera's largest lending protocol lost $9.05M after Supra's on-chain oracle verifier passed a price update carrying a cryptographically empty BLS signature. The pairing check returned true for zeroed inputs because both sides reduced to the mathematical identity point — letting an attacker borrow millions against three dollars of collateral.

Root Cause

The Supra oracle verifier on Hedera contained a critical flaw in its BLS (Boneh-Lynn-Shacham) signature validation logic. When a price update carried a zeroed-out signature and public key, the contract's pairing check still returned true because both values resolved to the elliptic-curve identity point.

// Simplified pseudocode of the vulnerable pattern:
function verifyBLS(bytes sig, bytes pubKey, bytes message) internal view returns (bool) {
    // If sig == 0 and pubKey == 0, pairing returns (1,1)==true trivially
    return Pairing.pairing(sig, G2_GENERATOR, neg(pubKey), hashToG2(message));
    // Missing guard:
    // require(sig != BLS_IDENTITY && pubKey != BLS_IDENTITY);
}

Additionally, the committee ID supplied in the malicious update was out of range; the lookup defaulted to the zero-key rather than reverting, removing the last safety net.

Attack Steps

StepActionDetail
1Deposit collateralAttacker deposited 250 SAUCE (~$3) in Bonzo Lend
2Submit poisoned price updateSent a Supra oracle update for SAUCE with zeroed BLS signature and zeroed public key; out-of-range committee ID returned zero key
3Pairing passesSupra verifier accepted the update; SAUCE price recorded at ~10^12 x true market value
4Borrow against inflated collateral8 seconds after false price landed, borrowed 6.63M USDC + 34.52M wrapped HBAR
5ExitFunds bridged off Hedera and partially laundered via cross-chain swaps

Impact

  • Loss: $9.05M (6.63M USDC + 34.52M wHBAR)
  • Protocol TVL: Bonzo Lend's TVL fell 77% immediately after the exploit
  • Ecosystem TVL: Hedera's total DeFi TVL dropped ~40% within 24 hours
  • Root location: Vulnerability was in Supra's oracle verifier, not Bonzo Lend's own contracts
  • Supra deployed a fix post-incident; Bonzo paused markets

Lessons for Auditors

  1. Validate identity-point inputs before any BLS/pairing check. Assert that both sig and pubKey are not the group identity element. A zeroed BLS signature trivially satisfies many pairing equations.
  2. Out-of-bounds committee lookups must revert, not default. Mapping or array lookups that silently return zero on out-of-range access are a dangerous failure mode. Add explicit bounds checks and require(committeeKey != bytes(0)).
  3. Lending protocols need price-deviation circuit-breakers. A sanity guard in the borrowing path that rejects prices deviating by more than N% from TWAP would have blocked this entirely.
  4. Third-party oracle dependencies inherit oracle risk. Bonzo Lend's own Solidity was correct. Audits must include the oracle adapter and its upstream verification logic.
attack patterns
oraclesdefi-lendingsignaturesprecision-math
sources