T
iTokenly

Bonzo Lend hack — July 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 11, 2026
Target typeLending protocol
Loss$9,050,000Published estimates range $9,050,000 to $10,060,000Price at time of incident
MethodOracle or price manipulationBonzo Lend priced collateral using Supra, a third-party oracle. Supra's on-chain verifier performed a BLS pairing check without first rejecting degenerate inputs, so a price update submitted with a zeroed signature and zeroed committee key made the pairing return true and was accepted as authentic. The attacker used this to inflate the recorded price of SAUCE by roughly twelve orders of magnitude, posted 250 SAUCE as collateral and borrowed out the pool's reserves. Bonzo's own contracts were not at fault.
ChainsOther
OutcomeUsers reimbursed

What happened

Bonzo Lend, the largest lending market on Hedera, was drained on 11 July 2026. Bonzo's incident report timestamps the first malicious transaction at 00:51:39 UTC and puts the principal extracted by the attacking wallet at $9.05 million, made up of 6,634,528.20 USDC and 34,518,389.36 wrapped HBAR. A second wallet borrowed roughly $1 million using the same technique and then identified itself in Bonzo's Discord as a white-hat responder intending to return the funds, which is why that amount sits outside the headline figure. CoinDesk, citing Bonzo, puts total principal borrowed during the incident at about $10.06 million before recovery; that wider figure includes the second wallet.

The fault was not in Bonzo's own contracts. Bonzo Lend took collateral prices from Supra, a third-party oracle. Supra's on-chain verifier validated BLS signatures with a pairing operation but did not first reject degenerate inputs, so a price update submitted with a zeroed signature and a zeroed committee key produced a pairing result of true and was written on-chain as authentic. The attacker used this to inflate the recorded price of SAUCE, the SaucerSwap token, by roughly twelve orders of magnitude against its real value of about 0.2 HBAR, deposited 250 SAUCE as collateral, and borrowed the pool's USDC and wrapped HBAR reserves against it.

Bonzo Lend was paused at 01:41 UTC and its points programme shortly after; the protocol's vaults, bridge and staking were unaffected. Supra acknowledged the flaw and deployed a fix to the verifier contract. Bonzo Lend's total value locked fell 77% within a day, and Hedera's overall DeFi total value locked fell about 40% to $25.7 million. Bonzo Finance Foundation later said it would fund the full recovery of affected Bonzo Lend positions as they stood immediately before the exploit, valued as of 00:51:39 UTC on 11 July 2026, backed by a recovery facility committed by the Hedera Foundation.

Sources

  1. Bonzo FinancePrimary · retrieved 2026-08-01
  2. Bonzo FinancePrimary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. BlockonomiSecondary · retrieved 2026-08-01

Official post-mortem: https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Bonzo Lend hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bonzo-lend
https://itokenly.com/hacks/bonzo-lend

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.