Go to app

Technical Mechanism: The "Zero-Signature" Bypass

Published 7/13/2026, 2:02:53 PM

The Bonzo Lend exploit on July 11, 2026, resulted in a $9.05 million loss and highlights a critical systemic vulnerability in how on-chain oracles verify cryptographic signatures. The incident was not caused by a flaw in Bonzo Lend’s lending logic, but by a "zero-signature" bypass in Supra’s oracle verifier contract on the Hedera network [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Technical Mechanism: The "Zero-Signature" Bypass

The attacker exploited a mathematical edge case in the BLS (Boneh-Lynn-Shacham) signature verification logic within the Supra verifier contract (requireHashVerified_V2).

Systemic Risk and Oracle Vulnerabilities

This exploit reveals that the security of DeFi protocols is increasingly dependent on the infrastructure verification layer rather than just the data accuracy itself.

MetricImpact DetailsSource
Total Stolen$9.05M (Primary attacker) + ~$1M (White-hat)Source
Bonzo TVL Drop77% decrease following the exploitSource
Hedera Ecosystem TVL40% drop within 24 hoursSource
Root CauseCryptographic verification failure (Supra Oracle)Source

Broader Implications for DeFi

The Bonzo Lend incident confirms a systemic pattern where BLS-based oracles may be vulnerable if they do not strictly validate non-zero inputs and subgroup membership. While traditional oracle attacks often involve market manipulation (e.g., Mango Markets), this exploit represents a cryptographic failure that could theoretically affect any protocol using similar push-model oracle configurations that lack robust input validation [Source: https://x.com/ilmeaalim/status/2075905177203417317].

Current Status:

While the specific mathematical flaw in the Supra verifier has been patched, the event serves as a warning that protocols must audit not only their own code but the underlying cryptographic assumptions of their third-party oracle providers.