Skip to main content
Sign in

Audit log

Every state-changing event for Supra Oracle — Bonzo Lend Attack Vector: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-09 12:29:38Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    HNKNBrQjwTUA…SisnwxFwsha256 → base58
    verifying row…
    canonical bytes (26041 B) ▸
    {"actor":"system:backfill","investigation_id":"c728ec71-a5d0-4641-9fd6-93840cd32777","kind":"publish","page_slug":"supra-oracle-bonzo-lend-attack-vector","published_at":"2026-08-09T12:29:38.865Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Supra Oracle — Bonzo Lend Attack Vector","sections":[{"content":"Supra (formerly SupraOracles) is a cross-chain oracle and blockchain infrastructure platform founded in 2020 and headquartered in Miami, Florida. The company was co-founded by CEO Joshua Tobkin, CBO Jon Jones, and Victor Ermolaev. Its stated mission is to supply oracle data feeds, decentralized verifiable randomness (dVRF), and an integrated smart contract platform to Web3 protocols across multiple blockchains. As of mid-2026, Supra has raised approximately $47.9 million across 30 distinct investors, with notable backers including Coinbase Ventures, Animoca Brands, HashKey Capital, Prosus Ventures, and Valor Equity Partners. Supra's oracle protocol research is led by Dr. Aniket Kate, credited with inventing KZG Polynomial Commitments. The platform supplies price feeds to DeFi protocols across chains including Arbitrum, Base, Polygon, Hedera, Fuse, and others.","heading":"Entity Background","severity":"low","sources":[{"credibility":2,"name":"Supra Company Profile — Tracxn","type":"other","url":"https://tracxn.com/d/companies/supra/__YZvfyBewAFSEndiqNFEspBR08evoXEfNejWUZalLTj4"},{"credibility":2,"name":"Supra (SUPRA) IEO Funding Rounds and Tokenomics — CryptoRank","type":"other","url":"https://cryptorank.io/ico/supra-oracles"}]},{"content":"The root cause of the Bonzo Lend exploit was a flaw in Supra's on-chain oracle verifier contract, specifically the function `requireHashVerified_V2`. The vulnerability allowed an attacker to submit a price update carrying a zeroed BLS (Boneh-Lynn-Shacham) signature — a signature whose byte value is entirely zeros and represents the mathematical identity element — rather than a valid cryptographic attestation from Supra's oracle committee.\n\nThe attack succeeded because the verifier accepted an invalid committee ID (value 2) that fell outside Supra's populated range. Instead of rejecting the out-of-range ID, the contract's lookup returned a public key of all zeros. When that zero public key was paired against the zero signature during the BLS pairing check, both sides of the underlying mathematical verification equation simultaneously became zero — the BLS identity element — causing the pairing to return true. The verifier misinterpreted this mathematically correct answer to the wrong question as proof of a genuine oracle committee signature.\n\nSecurity researcher Cos summarized the flaw: 'both sides of the underlying mathematical verification equation simultaneously became 0.' Bonzo Finance's own incident report described the outcome as: 'The verifier trusted a correct answer to the wrong question.'\n\nSupra's post-exploit fix introduced three retrospective checks: range validation on committee ID lookup; rejection of identity element keys and signatures; and on-curve validation before pairing checks. CEO Joshua Tobkin stated publicly that 'the identity-element check alone would have prevented this attack.'\n\nCritically, Tobkin acknowledged that the vulnerable code had been 'live, transparent, for two years' before exploitation, visible to all on-chain yet undetected by any human auditor. He attributed the eventual discovery to AI-assisted code analysis, describing a new adversarial capability that 'reads every line, every branch, every edge case' with greater persistence than human review.","heading":"The Supra Oracle Verifier Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"Bonzo Finance — Rekt News Post-Mortem","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit (Official)","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"}]},{"content":"One of the most significant findings of the post-incident investigation is that Supra deployed a security patch resolving this verifier flaw to at least 11 blockchain deployments between June 29 and July 3, 2026 — more than a week before the Hedera attack — but left the Hedera deployment unpatched. Analyst Tomachi Anura confirmed that all verified upgrades on the 11 chains resolved to 'the same 17,354-char guarded SupraSValueFeedVerifier,' establishing that the Hedera contract differed from the patched version.\n\nKnown patch dates prior to the exploit include: Base (June 29, 2026) and Polygon (July 3, 2026), among 9 other chains. The Hedera contract was patched approximately 6 hours after the $9.05 million exploit occurred on July 11, 2026. The Fuse network was also patched post-exploit.\n\nPlasma analyst Usmann Khan noted that upgrades had occurred on 'more important networks like Arbitrum' while Hedera remained untouched. Supra has not publicly disclosed whether it was aware of the vulnerability at the time of the June 29 – July 3 patches, or whether the Hedera omission was unintentional. This disclosure gap is material: if Supra identified the flaw and began patching without notifying dependent protocols or completing a full rollout, protocols like Bonzo Lend were exposed without warning.","heading":"Selective Patching: 11 Chains Before Hedera","severity":"critical","sources":[{"credibility":2,"name":"Supra Patched Oracle on 11 Other Chains Before $9M Hedera Exploit — Protos","type":"news_article","url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"credibility":2,"name":"Bonzo Finance — Rekt News Post-Mortem","type":"research","url":"https://rekt.news/bonzo-finance-rekt"}]},{"content":"The attack unfolded with precision on July 11, 2026 on the Hedera mainnet. At 00:39:53 UTC, Wallet A deposited 250 SAUCE tokens — worth approximately $3 at market prices — as collateral into Bonzo Lend. At 00:40:00 UTC, a normal price update was submitted, likely as reconnaissance to confirm the oracle's responsiveness. At 00:51:39 UTC, a manipulated price update was submitted to Supra's oracle, inflating the SAUCE token's recorded price by approximately twelve orders of magnitude above its actual trading value of ~0.2 HBAR.\n\nThe fraudulent price update was accepted by Supra's verifier via the zeroed-signature bypass. Eight seconds later, at 00:51:47 UTC, Wallet A borrowed 6,634,528 USDC. At 00:51:57 UTC, Wallet A borrowed an additional 34.5 million Wrapped HBAR (WHBAR). Bonzo Lend's smart contracts operated as designed throughout — they calculated borrowing capacity from the oracle-supplied price and issued the loans accordingly. The manipulation was entirely oracle-layer, not application-layer.\n\nBetween approximately 01:11 and 01:36 UTC, a second wallet (Wallet B) borrowed approximately $1 million under the still-inflated oracle price. At 01:36 UTC, legitimate oracle publishing restored SAUCE to its normal price (~0.1964 HBAR). At 01:41 UTC, Bonzo Lend was paused. Wallet B later contacted the Bonzo team via Discord, self-identified as a white-hat responder, and pledged to return the borrowed funds; Bonzo excluded this amount from the headline loss figure.\n\nStolen assets were moved across chains rapidly via LayerZero and Stargate bridge protocols, landing on Arbitrum, Base, and Ethereum. Wallet A ultimately received approximately $5.25 million equivalent (reported as 2,360 ETH and 15.58 WBTC). Funds were subsequently routed through Tornado Cash. A white-hat hacker separately recovered approximately $1 million.","heading":"Attack Mechanics and Execution Timeline","severity":"critical","sources":[{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit (Official)","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":2,"name":"Bonzo Finance — Rekt News Post-Mortem","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":2,"name":"Hedera Lending Protocol Bonzo Lend Hit for $9 Million After Supra Verifier Accepts Manipulated Price Update — The Block","type":"news_article","url":"https://www.theblock.co/post/407960/hedera-lending-protocol-bonzo-lend-hit-for-9-million-after-supra-verifier-accepts-manipulated-price-update"},{"credibility":2,"name":"Hedera's Biggest DeFi Lender Bonzo Lend Hacked for $9M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/11/hederas-biggest-defi-lender-bonzo-lend-hacked-for-9m-5-25m-bridged-to-ethereum/"}]},{"content":"The direct loss to Bonzo Lend was approximately $9.05 million extracted by the malicious actor (Wallet A), with an additional ~$1 million borrowed by Wallet B and expected to be returned. Bonzo Lend's total value locked (TVL) fell by approximately 77% within 24 hours of the exploit. The Hedera network's aggregate DeFi TVL declined by approximately 40% in the same period, falling to approximately $25.7 million.\n\nBonzo Finance's auxiliary products — Bonzo Vaults, Bonzo Bridge, and single-sided staking — were not directly affected and remained operational. The Bonzo Points program was paused alongside Bonzo Lend. Bonzo Finance stated that the SAUCE token's actual market price remained stable throughout the incident, confirming the manipulation was entirely at the oracle layer rather than reflecting genuine market volatility.","heading":"Financial Impact and Market Consequences","severity":"high","sources":[{"credibility":1,"name":"Lending Protocol Bonzo Loses 77% of Value Locked as $9 Million Oracle Exploit Rattles Hedera — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"credibility":1,"name":"Bonzo Lend's Total Value Locked Plunges 77% as $9 Million Oracle Exploit Rattles Hedera — CoinDesk (Yahoo Finance)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/hedera-network-reportedly-hit-exploit-092407541.html"}]},{"content":"Bonzo Lend's smart contracts had passed audits by Halborn, a well-regarded blockchain security firm. However, Bonzo's bug bounty policy explicitly excluded 'third-party contracts not directly associated with Bonzo Finance,' meaning the Supra verifier was out of scope for both Bonzo's audits and its bounty program. This contractual scoping left a critical dependency unexamined.\n\nSupra's named audit for its oracle verifier was conducted by MoveBit and was focused on an Aptos-based implementation. According to post-exploit analysis reported by Rekt News, the vulnerable Hedera verifier contract never underwent formal audit. The two-year window during which the zero-signature flaw existed on-chain without detection highlights a gap in both Supra's internal security review process and the broader ecosystem's approach to oracle infrastructure auditing.\n\nBonzo Finance's team explicitly stated: 'The pool calculated collateral value and borrowing capacity using the price the oracle supplied. Given a manipulated input, the protocol simply produced the output its code specifies.' This framing shifts accountability to the oracle provider while illustrating the systemic dependency that oracle-reliant protocols carry.","heading":"Audit Gaps and Accountability","severity":"high","sources":[{"credibility":2,"name":"Bonzo Finance — Rekt News Post-Mortem","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit (Official)","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"}]},{"content":"Supra operates as a cross-chain oracle network supplying price data to protocols across multiple blockchain ecosystems. The Bonzo exploit demonstrated that a single flaw in a shared oracle verifier contract can drain any downstream lending or derivatives protocol that trusts that feed without independent validation. Because the vulnerable verifier was deployed across many chains — with documented instances on at least Hedera, Fuse, Base, Polygon, and Arbitrum — any protocol depending on Supra price feeds during the unpatched window faced the same theoretical attack vector.\n\nThe selective patching pattern — where Supra upgraded 11 chains between June 29 and July 3, 2026 but left Hedera unpatched — raises the question of whether a similarly incomplete patch rollout could leave other chains exposed in a future incident. Industry analysts cited by CryptoRank noted that 'when a single oracle provides the pricing for a suite of applications, an error at the supplier can cascade,' and called for oracle redundancy design where protocols require multiple independent price sources before executing large loans.\n\nThe Solido Money protocol separately suffered an exploit on July 23, 2026, involving a pricing error in its Solido Cash product and the SUPRA token, resulting in approximately 293.7 million SUPRA tokens stolen (worth near $900,000 at the time), though that incident had distinct mechanics from the Bonzo verifier flaw.\n\nProtocols considering Supra oracle integration should treat oracle validation as security-critical infrastructure and verify that the specific chain deployment has received the most recent security patches, independent of other chains in the Supra network.","heading":"Systemic Risk to Supra-Dependent Protocols","severity":"high","sources":[{"credibility":2,"name":"Bonzo Exploit Drains $9M From Hedera's Largest Lending Protocol, Underscoring Cross-Chain Oracle Risk — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/d9859-bonzo-exploit-drains-9m-from-hederas-largest-lending-protocol-underscoring-cross-chain-oracle-risk"},{"credibility":2,"name":"Supra Patched Oracle on 11 Other Chains Before $9M Hedera Exploit — Protos","type":"news_article","url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"credibility":2,"name":"Solido Foundation Loses 90% of Stolen SUPRA Tokens in Oracle Attack — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/amp/story/news/solido-foundation-loses-90-of-stolen-supra-tokens-in-oracle-attack"}]},{"content":"Supra CEO Joshua Tobkin addressed the attacker publicly via social media in the days following the exploit. Tobkin acknowledged that the vulnerable code had been visible on-chain 'for two years straight' through an entire bull market, available to any reviewer, yet undetected. He attributed the eventual discovery to AI-assisted code analysis, describing a novel adversarial class capable of reviewing code with 'a persistence no human auditor can match.'\n\nTobkin publicly offered the attacker a negotiated settlement: retain $100,000, return the remainder of the stolen funds, receive immunity from prosecution, and accept a standing job offer at Supra. He established a 72-hour return window and provided a dedicated recovery address (publicly cited as 0x913BDd...1cC). He also stated that a non-returning attacker would face a growing bounty — increasing 10% annually, indefinitely. As of available reporting, no funds were returned by Wallet A.\n\nSupra confirmed that the fix was deployed to the Hedera verifier contract approximately 6 hours after the exploit. Bonzo Finance Labs and the Bonzo Foundation indicated they were coordinating recovery efforts, including working with Wallet B (the alleged white-hat participant) to recover the approximately $1 million in that wallet.","heading":"Supra's Public Response and Bounty Offer","severity":"medium","sources":[{"credibility":3,"name":"Bonzo Hack — Supra Co-Founder Statement — CoinSpectator","type":"news_article","url":"https://coinspectator.com/mainstream/2026/07/13/bonzo-hack-supra-cofounder/"},{"credibility":2,"name":"Supra Patched Oracle on 11 Other Chains Before $9M Hedera Exploit — Protos","type":"news_article","url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit (Official)","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"}]},{"content":"Bonzo Finance's reliance on Supra oracle feeds was itself a product of a prior infrastructure decision. According to reporting, Bonzo Finance shifted from Chainlink oracles to Supra in March 2024, citing Chainlink's absence from the Hedera network at the time. This transition was a reasonable response to the available oracle landscape on Hedera but placed Bonzo in a position of dependence on a less-established provider whose Hedera-specific verifier had not been formally audited for the chain's deployment environment.","heading":"Oracle Dependency Transition on Hedera","severity":"medium","sources":[{"credibility":2,"name":"Bonzo Finance TVL Collapses 77% After $9M Oracle Exploit on Hedera — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/bonzo-finance-tvl-collapses-77-after-9m-oracle-exploit-on-hedera/"}]}],"sources_used":[{"credibility":1,"name":"Bonzo Lend Incident Report: Oracle Provider Exploit — Bonzo Finance (Official)","type":"official","url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"credibility":1,"name":"Lending Protocol Bonzo Loses 77% of Value Locked as $9 Million Oracle Exploit Rattles Hedera — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"credibility":1,"name":"Hedera Lending Protocol Bonzo Lend Hit for $9 Million After Supra Verifier Accepts Manipulated Price Update — The Block","type":"news_article","url":"https://www.theblock.co/post/407960/hedera-lending-protocol-bonzo-lend-hit-for-9-million-after-supra-verifier-accepts-manipulated-price-update"},{"credibility":2,"name":"Bonzo Finance — Rekt News Post-Mortem","type":"research","url":"https://rekt.news/bonzo-finance-rekt"},{"credibility":2,"name":"Supra Patched Oracle on 11 Other Chains Before $9M Hedera Exploit — Protos","type":"news_article","url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"credibility":2,"name":"Bonzo Lend Paused After $9 Million Oracle Exploit — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/bonzo-lend-9m-oracle-exploit-hedera/"},{"credibility":2,"name":"Bonzo Lend Loses $9.05M in Hedera Oracle Exploit Linked to Supra Flaw — Blockonomi","type":"news_article","url":"https://blockonomi.com/bonzo-lend-loses-9-05m-in-hedera-oracle-exploit-linked-to-supra-flaw"},{"credibility":2,"name":"Bonzo Exploit Drains $9M From Hedera's Largest Lending Protocol, Underscoring Cross-Chain Oracle Risk — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/d9859-bonzo-exploit-drains-9m-from-hederas-largest-lending-protocol-underscoring-cross-chain-oracle-risk"},{"credibility":2,"name":"Bonzo Finance TVL Collapses 77% After $9M Oracle Exploit on Hedera — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/bonzo-finance-tvl-collapses-77-after-9m-oracle-exploit-on-hedera/"},{"credibility":2,"name":"Bonzo Lend's $9M Oracle Exploit: Why Verifier Assumptions Are DeFi's Weak Link — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/bonzo-lend-9m-oracle-verifier"},{"credibility":2,"name":"Hedera's Biggest DeFi Lender Bonzo Lend Hacked for $9M, $5.25M Bridged to Ethereum — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/11/hederas-biggest-defi-lender-bonzo-lend-hacked-for-9m-5-25m-bridged-to-ethereum/"},{"credibility":2,"name":"Bonzo Finance Loses $9M in Oracle Attack via SAUCE Price Manipulation — Phemex News","type":"news_article","url":"https://phemex.com/news/article/bonzo-finance-loses-9-million-in-oracle-attack-exploiting-sauce-price-manipulation-92670"},{"credibility":2,"name":"Solido Foundation Loses 90% of Stolen SUPRA Tokens in Oracle Attack — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/amp/story/news/solido-foundation-loses-90-of-stolen-supra-tokens-in-oracle-attack"},{"credibility":2,"name":"Supra Company Profile — Tracxn","type":"other","url":"https://tracxn.com/d/companies/supra/__YZvfyBewAFSEndiqNFEspBR08evoXEfNejWUZalLTj4"},{"credibility":2,"name":"Supra (SUPRA) IEO Funding Rounds and Tokenomics — CryptoRank","type":"other","url":"https://cryptorank.io/ico/supra-oracles"},{"credibility":3,"name":"Bonzo Hack — Supra Co-Founder Statement — CoinSpectator","type":"news_article","url":"https://coinspectator.com/mainstream/2026/07/13/bonzo-hack-supra-cofounder/"}],"summary":"On July 11, 2026, Hedera's largest lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a signature verification flaw in Supra's on-chain oracle verifier contract. The vulnerable code had been live for at least two years and was deployed to 11 other chains — all of which received a security patch in the days before the Hedera attack — while the Hedera instance remained unpatched. Supra, founded in 2020 and backed by Coinbase Ventures and other institutional investors, is a cross-chain oracle and infrastructure network whose verifier flaw carries systemic risk to any dependent protocol.","timeline":[{"date":"2024-03-01","event":"Bonzo Finance migrates from Chainlink to Supra oracles on Hedera, citing Chainlink's absence from the network.","source":"Blockchain Reporter","source_url":"https://blockchainreporter.net/bonzo-finance-tvl-collapses-77-after-9m-oracle-exploit-on-hedera/"},{"date":"2026-06-29","event":"Supra deploys patched SupraSValueFeedVerifier to Base network — earliest confirmed patch in the pre-exploit rollout.","source":"Protos","source_url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"date":"2026-07-03","event":"Supra patches oracle verifier on Polygon. At least 11 chains total receive the fix between June 29 and July 3, 2026. Hedera deployment is not patched.","source":"Protos","source_url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"date":"2026-07-11","event":"At 00:39:53 UTC, attacker (Wallet A) deposits 250 SAUCE tokens (~$3 value) as collateral into Bonzo Lend on Hedera.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 00:51:39 UTC, attacker submits manipulated SAUCE price to Supra oracle, inflated ~12 orders of magnitude. Supra verifier accepts the zeroed BLS signature.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 00:51:47 UTC, Wallet A borrows 6,634,528 USDC. At 00:51:57 UTC, Wallet A borrows 34.5 million WHBAR. Total extracted: ~$9.05 million.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"Between 01:11–01:36 UTC, Wallet B (alleged white-hat) borrows ~$1 million under the still-manipulated price window.","source":"Bonzo Finance Incident Report","source_url":"https://bonzo.finance/blog/bonzo-lend-incident-report-oracle-provider-exploit"},{"date":"2026-07-11","event":"At 01:36 UTC, legitimate oracle publishing restores SAUCE to normal price (~0.1964 HBAR). At 01:41 UTC, Bonzo Lend is paused.","source":"Blockonomi","source_url":"https://blockonomi.com/bonzo-lend-loses-9-05m-in-hedera-oracle-exploit-linked-to-supra-flaw"},{"date":"2026-07-11","event":"Stolen assets bridged via LayerZero/Stargate to Arbitrum, Base, and Ethereum. Wallet A receives approximately $5.25 million equivalent (2,360 ETH, 15.58 WBTC). Funds subsequently routed through Tornado Cash.","source":"Rekt News","source_url":"https://rekt.news/bonzo-finance-rekt"},{"date":"2026-07-11","event":"Supra deploys the patched verifier to Hedera mainnet approximately 6 hours after the exploit. Fuse network also patched post-exploit.","source":"Protos","source_url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"date":"2026-07-11","event":"Hedera network DeFi TVL falls ~40% within 24 hours to ~$25.7 million. Bonzo Lend TVL falls 77%.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/07/11/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera"},{"date":"2026-07-13","event":"Supra CEO Joshua Tobkin publicly addresses the attacker, acknowledges two-year on-chain exposure of the vulnerable code, cites AI-assisted hacking as likely exploit vector, and offers $100,000 bounty + immunity + job offer for fund return. No funds recovered from Wallet A as of reporting.","source":"CoinSpectator / Protos","source_url":"https://protos.com/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit/"},{"date":"2026-07-23","event":"Solido Money protocol suffers a separate exploit involving SUPRA token pricing errors in its Solido Cash product; approximately 293.7 million SUPRA tokens stolen (~$900,000 at time of attack).","source":"Analytics Insight","source_url":"https://www.analyticsinsight.net/amp/story/news/solido-foundation-loses-90-of-stolen-supra-tokens-in-oracle-attack"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision abaf4555-91c4-4d0e-89d9-f6001a470e73
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.