Zeroed oracle signature let $9.05M be borrowed from Bonzo Lend

A zeroed oracle signature and a zeroed committee key passed Bonzo Lend’s verifier, letting a wallet borrow $9.05 million against 250 SAUCE and pausing withdrawals.

Bonzo Lend paused withdrawals after its oracle verifier accepted a zeroed signature and a zero committee public key, allowing a wallet to borrow about $9.05 million in principal against 250 SAUCE.

The incident occurred in the early hours of July 13 UTC. Wallet A deposited 250 SAUCE, a token worth only a few dollars on open markets, and submitted a SAUCE/wHBAR price update that inflated the token’s value by roughly 12 orders of magnitude while the market price stayed near 0.2 HBAR. Eight seconds after the manipulated price was written to on-chain oracle storage, the wallet borrowed 6.63 million USDC and then 34.5 million wrapped HBAR, totaling about $9.05 million at the protocol’s reference prices. A second wallet, Wallet B, borrowed about $1 million while the abnormal price was live and later contacted Bonzo identifying itself as a white-hat responder; Bonzo counts roughly $1 million as recovered but the final tally remains unsettled.

The submitted price update contained no valid committee signature: the signature field was [0,0] and the referenced committee public key was the mathematical identity, the point at infinity. Supra’s verifier passed those inputs to Hedera’s pairing precompile. Because both inputs represented the identity element, the pairing equation returned true. The verifier treated that result as proof of a committee signature because it did not reject zero, identity or off-subgroup inputs before calling the pairing.

Bonzo’s lending contracts then applied their programmed loan-to-value rules using the stored oracle price and issued the loans. Bonzo Finance Labs and the Bonzo Finance Foundation paused the Bonzo Lend and Bonzo Points products. The protocol’s status page lists affected markets as under maintenance and warns that liquidity providers cannot withdraw funds. Bonzo is developing a recovery plan and determining recovery terms, reimbursement procedures and conditions for reopening; no timeline or user-facing withdrawal arrangements have been announced.

Supra patched the verifier after the incident. Both teams still need to confirm through regression testing that the verifier now rejects zero, identity and other invalid inputs. Bonzo is also evaluating whether to add price-deviation checks, tighten collateral parameters or change how available assets will be handled when withdrawals resume.

Liquidity providers remain unable to withdraw and await the recovery measures that Bonzo and its partners put in place.

Articles by this author