Skip to main content
Sign in
Bonzo Finance1 decision on this page

Audit log

Every state-changing event for Bonzo Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-29 23:11:12Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    4fdLgCGXejvF…K7jtLzySsha256 → base58
    verifying row…
    canonical bytes (24742 B) ▸
    {"actor":"system:backfill","investigation_id":"eb7d60ce-600d-4768-9ba4-a4f9e2120583","kind":"publish","page_slug":"bonzo-finance","published_at":"2026-07-29T23:11:12.789Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bonzo Finance","sections":[{"content":"Bonzo Finance is an open-source, non-custodial lending and borrowing protocol built on the Hedera network. It is based on Aave v2 and adapted to both Hedera's EVM compatibility layer and its native Hedera Token Service (HTS). The protocol was developed by Bonzo Finance Labs, co-founded by Brady Gentile (Co-Founder and CEO) and Gaurang (Co-Founder and CTO). Brady Gentile holds a B.S. in Management (Entrepreneurship) from Arizona State University and previously worked at both Hedera and Swirlds Labs in marketing and product roles, accumulating over six years of experience in the Hedera ecosystem. The protocol launched on Hedera mainnet on October 28, 2024, and positioned itself as 'the liquidity layer of Hedera.' Prior to the July 2026 exploit, Bonzo Lend was described as Hedera's largest lending protocol. Bonzo Finance Labs had engaged Halborn Security to conduct a smart contract audit of the protocol's code; that audit concluded that Bonzo Lend's own contracts contained no critical vulnerabilities. The Supra oracle infrastructure that Bonzo Lend relied upon was outside the scope of that engagement.","heading":"Protocol Background","severity":"low","sources":[{"credibility":1,"name":"Bonzo Finance Pioneering Lending and Borrowing for Hedera DeFi","type":"official","url":"https://bonzo.finance/blog/bonzo-finance-pioneering-lending-and-borrowing-for-hedera-defi"},{"credibility":2,"name":"Bonzo Finance Partners with LWorks to Launch DeFi Lending on Hedera — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/news-release/2024/12/05/2992457/0/en/Bonzo-Finance-Partners-with-LWorks-to-Launch-DeFi-Lending-on-Hedera.html"},{"credibility":1,"name":"Bonzo Finance Team — Bonzo Finance Documentation","type":"official","url":"https://docs.bonzo.finance/hub/contributors/team"},{"credibility":2,"name":"Finance Contracts Audit — Halborn","type":"research","url":"https://www.halborn.com/audits/bonzo-finance/smart-contract-assessment-78bdba"},{"credibility":1,"name":"Hedera Case Study: Bonzo Finance","type":"official","url":"https://hedera.com/case-study/bonzo/"}]},{"content":"On July 11, 2026, at approximately 00:51:39 UTC, an attacker identified as Wallet A (Hedera account 0.0.10633526; EVM address 0x9a4966152f6e10b33cb7a37975e8619816d6a494) exploited a critical flaw in Supra's on-chain oracle verifier contract (Hedera account 0.0.4323006, function requireHashVerified_V2) to drain approximately $9.05 million from Bonzo Lend.\n\nThe attack proceeded as follows. At 00:39:53 UTC, Wallet A deposited 250 SAUCE tokens — worth approximately $3 at prevailing market prices — as collateral into Bonzo Lend. At 00:40:00 UTC a normal price update was submitted, likely as reconnaissance. At 00:51:39 UTC, the attacker submitted a manipulated price update for the SAUCE/wHBAR pair (oracle pair ID 425) carrying a zeroed BLS signature. The Supra verifier failed to reject this forged input before performing the cryptographic pairing check. Because both the signature and the referenced committee public key were zero — the BLS identity elements — the pairing equation evaluated to true on both sides, allowing the forged update to pass as genuine. The false price inflated SAUCE's value by approximately 12 orders of magnitude above its actual trading price of approximately 0.1964 HBAR.\n\nEight seconds after the false price was accepted, Wallet A borrowed 6,634,528 USDC and over 34.5 million wrapped HBAR from Bonzo Lend's liquidity pools, completing the extraction of approximately $9.05 million. The entire borrowing operation was completed within one minute of the manipulated price becoming active.\n\nA second wallet (Wallet B, Hedera account 0.0.683607) also deposited SAUCE and borrowed approximately $1 million while the false price remained active, between approximately 01:11 and 01:36 UTC. Wallet B subsequently contacted the Bonzo Finance team via its official Discord server, identified itself as a white-hat responder, and indicated intent to return the borrowed funds. Bonzo Finance excluded Wallet B's funds from its headline loss total of $9.05 million.\n\nAt 01:36 UTC, a legitimate oracle publisher restored the SAUCE price to normal market levels. At 01:41 UTC, Bonzo Lend was paused. At 05:50 UTC, Bonzo Points was also paused.","heading":"July 11, 2026 Oracle Exploit — Attack Mechanics","severity":"critical","sources":[{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":1,"name":"Lending protocol Bonzo loses 77% of value locked as $9 million oracle exploit rattles Hedera — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"credibility":2,"name":"Bonzo Lend Loses $9.05M in Hedera Oracle Exploit Linked to Supra Flaw — Blockonomi","type":"news_article","url":"https://blockonomi.com/bonzo-lend-loses-9-05m-in-hedera-oracle-exploit-linked-to-supra-flaw"},{"credibility":2,"name":"Bonzo Finance — Rekt News","type":"research","url":"https://rekt.news/bonzo-finance-rekt"}]},{"content":"The exploit did not originate in Bonzo Finance's own smart contracts. Hedera and Bonzo Finance confirmed that Bonzo Lend's contracts and Hedera's core network were not compromised. The root cause was a critical flaw in Supra's oracle verifier contract deployed on Hedera.\n\nSupra's requireHashVerified_V2 function failed to validate that the cryptographic signature and committee public key inputs were non-zero before accepting the result of a BLS pairing check. When the attacker submitted a price update referencing an out-of-range committee ID (value of 2, outside the populated range), the system returned a zero public key. Paired with a zeroed BLS signature — both being the BLS identity element, also called the 'point at infinity' — the pairing equation held mathematically true on both sides simultaneously, causing the verifier to accept the forged price update as valid despite the absence of any legitimate cryptographic signature.\n\nRekt News characterized the failure as the verifier 'trusted a correct answer to the wrong question' — the cryptographic precompile correctly evaluated whether a pairing equation held, but the verifier omitted mandatory checks that would have identified the inputs as degenerate and invalid.\n\nThe flawed verifier contract had been publicly visible on-chain for approximately two years before exploitation. According to Rekt News, the contract had never undergone a security review; Supra's only named oracle audit covered contracts written in Move for the Aptos blockchain — an entirely different environment. Additionally, Bonzo Finance's own bug bounty program explicitly classified third-party dependencies as out-of-scope, meaning the vulnerability would not have triggered a reward had it been discovered and disclosed through that channel.\n\nFollowing the exploit, Supra acknowledged the flaw and deployed a patched version of the verifier contract. The patch introduced three independent validation steps that were absent in the original: range validation on the committee lookup, rejection of identity-element keys and signatures, and on-curve validation before cryptographic operations. Supra stated that 'the identity-element check alone would have prevented this attack.'","heading":"Root Cause: Supra Oracle BLS Signature Verification Flaw","severity":"critical","sources":[{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":2,"name":"Bonzo Finance — Rekt News","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"},{"credibility":2,"name":"A zeroed signature let a hacker drain nine million dollars from Hedera's biggest lender — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-zeroed-signature-let-a-hacker-drain-nine-million-dollars-from-hederas-biggest-lender/"}]},{"content":"The primary attacker (Wallet A) extracted approximately 6.63 million USDC and more than 34.5 million wrapped HBAR from Bonzo Lend within seconds of the manipulated price becoming active. According to Rekt News analysis, the stolen assets were subsequently bridged across multiple networks including Arbitrum, Base, and Ethereum before reaching the Tornado Cash mixer within hours of the attack. Final tracked holdings were reported at approximately $5.25 million, including approximately 2,360 ETH and 15.58 WBTC, following conversion to more liquid assets.\n\nA second wallet (EVM address 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e) was also identified in on-chain analysis. Wallet B (Hedera account 0.0.683607) borrowed approximately $1 million during the window when the false SAUCE price remained active and subsequently identified itself as a white-hat responder; Bonzo Finance treated its activity separately from the primary theft.\n\nAs of late July 2026, the primary attacker's funds had not been recovered.","heading":"Fund Movement and On-Chain Trail","severity":"critical","sources":[{"credibility":2,"name":"Bonzo Finance — Rekt News","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"}]},{"content":"The exploit had an immediate and significant impact on Hedera's DeFi ecosystem. Bonzo Lend's total value locked collapsed by approximately 77% in the immediate aftermath. Hedera's network-wide TVL dropped by nearly 40% within 24 hours, falling to approximately $25.7 million.\n\nHBAR, Hedera's native token, was trading at approximately $0.067 to $0.069 in the days following the incident, down approximately 71% year-over-year, though the exact portion of this decline attributable to the exploit versus broader market conditions is not established.\n\nThe exploit occurred against a backdrop of otherwise positive institutional signals for Hedera: Lloyds Banking Group, Aberdeen, and Archax executed what was described as the United Kingdom's first foreign exchange transaction using tokenized real-world assets on Hedera around the same period, illustrating a contrast between Hedera's institutional adoption trajectory and its DeFi security track record.\n\nBonzo Lend was identified as Hedera's largest lending protocol at the time of the exploit, meaning the incident represented a disproportionate share of liquidity removed from the network's DeFi sector.","heading":"Market and Ecosystem Impact","severity":"high","sources":[{"credibility":1,"name":"Lending protocol Bonzo loses 77% of value locked as $9 million oracle exploit rattles Hedera — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"credibility":2,"name":"HBAR News Today: Hedera's TVL Falls 40% After $9.05M Bonzo Lend Exploit — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/54f82-hbar-news-today"},{"credibility":2,"name":"Bonzo Finance TVL Collapses 77% After $9M Oracle Exploit on Hedera — BlockchainReporter","type":"news_article","url":"https://blockchainreporter.net/bonzo-finance-tvl-collapses-77-after-9m-oracle-exploit-on-hedera/"}]},{"content":"Following the exploit, Bonzo Finance Labs and the Bonzo Finance Foundation coordinated an immediate response. Bonzo Lend and Bonzo Points were paused on July 11, 2026; Bonzo Vaults, Bonzo Bridge, and single-sided staking continued to operate.\n\nOn approximately July 17, 2026, the Bonzo Finance Foundation announced that affected users would receive advances equal to the full value of their positions as they stood immediately before the exploit. The Hedera Foundation committed a facility to back this recovery. The team stated that funding would be designated solely for recouping individual user losses and would not be used for any other purpose. Users were told no action was required, with full participation details to follow in a subsequent announcement.\n\nBonzo Finance also stated that new smart contracts for a relaunched Bonzo Lend would undergo a security audit by Halborn before deployment on Hedera mainnet. The team emphasized that no rushed timeline had been set, prioritizing security review over speed of relaunch.\n\nThe team publicly cautioned users against scams impersonating the recovery program, noting that no legitimate communication would request private keys or seed phrases.\n\nSupra acknowledged its oracle contract's flaw, deployed a patched verifier, and engaged with Bonzo Finance's recovery coordination efforts.","heading":"Protocol Response and Recovery Plan","severity":"medium","sources":[{"credibility":2,"name":"Bonzo to Restore Pre-Exploit Positions with Hedera Backing — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/bonzo-to-restore-pre-exploit-positions-with-hedera-backing/"},{"credibility":2,"name":"Bonzo Lend paused after $9 million oracle exploit — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/bonzo-lend-9m-oracle-exploit-hedera/"},{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"}]},{"content":"The Bonzo Finance exploit surfaced a structural gap in common DeFi security practices: protocol-level smart contract audits do not inherently cover the security of third-party oracle infrastructure. Halborn's pre-launch audit of Bonzo Finance's contracts found no critical vulnerabilities in Bonzo Lend's own code, and this assessment was accurate — the failure point was entirely external.\n\nThe vulnerable Supra oracle verifier contract was reportedly publicly visible on-chain for approximately two years before being exploited. According to analysis published by Rekt News, Supra's only documented audit covered contracts written in Move for the Aptos blockchain and did not apply to the Hedera deployment. No dedicated security review of the flawed verifier was publicly identified prior to the exploit.\n\nBonzo Finance's bug bounty scope explicitly excluded third-party dependencies, which would have prevented any researcher who discovered the Supra flaw from being compensated for disclosing it through Bonzo's program.\n\nSecurity commentary following the exploit identified systemic recommendations for DeFi protocols relying on on-demand oracles: per-asset borrowing caps to limit exposure from any single price feed; application-layer deviation checks that reject anomalous price updates before they reach borrowing logic; dual-source price verification; and dedicated security reviews of oracle verifier contracts as a distinct audit scope. The incident was characterized by analysts as illustrating that 'the oracle did not need to be wrong about price — the verifier only needed to be wrong about trust.'","heading":"Audit Scope and Oracle Risk Considerations","severity":"high","sources":[{"credibility":2,"name":"Inside Bonzo Lend's $9M Exploit — Why Secure Smart Contracts Couldn't Stop It — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/inside-bonzo-lends-9m-exploit-why-secure-smart-contracts-couldnt-stop-it/"},{"credibility":2,"name":"Bonzo Finance — Rekt News","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"},{"credibility":2,"name":"CASE STUDY: This Latest Crypto Exploit Reveals Vulnerabilities Within DeFi Oracles — BitKE","type":"news_article","url":"https://bitcoinke.io/2026/07/the-bonzo-lend-exploit/"}]}],"sources_used":[{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":1,"name":"Lending protocol Bonzo loses 77% of value locked as $9 million oracle exploit rattles Hedera — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"credibility":2,"name":"Bonzo Lend Loses $9.05M in Hedera Oracle Exploit Linked to Supra Flaw — Blockonomi","type":"news_article","url":"https://blockonomi.com/bonzo-lend-loses-9-05m-in-hedera-oracle-exploit-linked-to-supra-flaw"},{"credibility":2,"name":"Bonzo Finance — Rekt News","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":2,"name":"Bonzo to Restore Pre-Exploit Positions with Hedera Backing — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/bonzo-to-restore-pre-exploit-positions-with-hedera-backing/"},{"credibility":2,"name":"Bonzo Lend paused after $9 million oracle exploit — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/bonzo-lend-9m-oracle-exploit-hedera/"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"},{"credibility":2,"name":"Inside Bonzo Lend's $9M Exploit — Why Secure Smart Contracts Couldn't Stop It — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/inside-bonzo-lends-9m-exploit-why-secure-smart-contracts-couldnt-stop-it/"},{"credibility":2,"name":"Finance Contracts Audit — Halborn","type":"research","url":"https://www.halborn.com/audits/bonzo-finance/smart-contract-assessment-78bdba"},{"credibility":1,"name":"Bonzo Finance Pioneering Lending and Borrowing for Hedera DeFi — Official Blog","type":"official","url":"https://bonzo.finance/blog/bonzo-finance-pioneering-lending-and-borrowing-for-hedera-defi"},{"credibility":1,"name":"Hedera Case Study: Bonzo Finance","type":"official","url":"https://hedera.com/case-study/bonzo/"},{"credibility":1,"name":"Bonzo Finance Team — Bonzo Finance Documentation","type":"official","url":"https://docs.bonzo.finance/hub/contributors/team"},{"credibility":1,"name":"Hedera-Based Bonzo Lend Loses $9 Million in Oracle Exploit — Yahoo Finance / CoinDesk","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/hedera-network-reportedly-hit-exploit-092407541.html"},{"credibility":2,"name":"Bonzo Finance Partners with LWorks to Launch DeFi Lending on Hedera — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/news-release/2024/12/05/2992457/0/en/Bonzo-Finance-Partners-with-LWorks-to-Launch-DeFi-Lending-on-Hedera.html"},{"credibility":2,"name":"CASE STUDY: This Latest Crypto Exploit Reveals Vulnerabilities Within DeFi Oracles — BitKE","type":"news_article","url":"https://bitcoinke.io/2026/07/the-bonzo-lend-exploit/"},{"credibility":2,"name":"Bonzo Exploit Drains $9M From Hedera's Largest Lending Protocol — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/d9859-bonzo-exploit-drains-9m-from-hederas-largest-lending-protocol-underscoring-cross-chain-oracle-risk"},{"credibility":2,"name":"A zeroed signature let a hacker drain nine million dollars from Hedera's biggest lender — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-zeroed-signature-let-a-hacker-drain-nine-million-dollars-from-hederas-biggest-lender/"}],"summary":"Bonzo Finance is an open-source, non-custodial lending and borrowing protocol deployed on the Hedera network, developed by Bonzo Finance Labs and launched on mainnet on October 28, 2024. On July 11, 2026, an attacker exploited a BLS signature verification flaw in a Supra oracle contract to artificially inflate the price of the SAUCE token by approximately 12 orders of magnitude, draining approximately $9.05 million in USDC and wrapped HBAR from Bonzo Lend. The incident caused Bonzo Lend's total value locked to collapse 77% and Hedera's overall DeFi TVL to drop nearly 40% within 24 hours; Bonzo Lend and Bonzo Points were subsequently paused, with the Hedera Foundation committing backing for full user position recovery.","timeline":[{"date":"2024-10-28","event":"Bonzo Finance launched on Hedera mainnet, positioning itself as the network's primary lending and borrowing protocol.","source":"Bonzo Finance Official Blog","source_url":"https://bonzo.finance/blog/bonzo-finance-mainnet-launch-recap-and-vision-for-the-future"},{"date":"2026-07-11","event":"At 00:39:53 UTC, attacker (Wallet A, Hedera account 0.0.10633526) deposited 250 SAUCE tokens worth approximately $3 as collateral into Bonzo Lend.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 00:51:39 UTC, Wallet A submitted a forged SAUCE/wHBAR price update with a zeroed BLS signature to Supra's oracle verifier. The verifier accepted it, inflating SAUCE price by approximately 12 orders of magnitude.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 00:51:47 UTC, Wallet A borrowed 6,634,528 USDC; at 00:51:57 UTC, borrowed 34.5 million WHBAR. Total theft approximately $9.05 million, completed within 8 seconds of the false price becoming active.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"Between approximately 01:11 and 01:36 UTC, Wallet B (Hedera account 0.0.683607) deposited SAUCE and borrowed approximately $1 million while the false price remained active.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 01:36 UTC, a legitimate Supra oracle publisher restored the SAUCE price to normal market levels.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 01:41 UTC, Bonzo Lend was paused. At 05:50 UTC, Bonzo Points was also paused.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"Hedera's total DeFi TVL fell nearly 40% within 24 hours, dropping to approximately $25.7 million. Bonzo Lend TVL collapsed 77%. CoinDesk published the first major news coverage.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"date":"2026-07-11","event":"Stolen assets were allegedly bridged across Arbitrum, Base, and Ethereum and routed through Tornado Cash mixer within hours of the attack, per Rekt News on-chain analysis.","source":"Rekt News","source_url":"https://rekt.news/bonzo-finance-rekt"},{"date":"2026-07-11","event":"Supra acknowledged the BLS signature verification flaw in its oracle verifier contract and deployed a patched version with three new validation checks.","source":"Blockonomi","source_url":"https://blockonomi.com/bonzo-lend-loses-9-05m-in-hedera-oracle-exploit-linked-to-supra-flaw"},{"date":"2026-07-17","event":"Bonzo Finance Foundation announced a full user position recovery program backed by a facility committed by the Hedera Foundation. Affected users were told advances equal to their pre-exploit positions would be distributed after a verification procedure.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/07/17/bonzo-to-restore-pre-exploit-positions-with-hedera-backing/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision d098e1e0-1b44-4a44-b645-f78cdca09f82
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.