Saturday, August 1, 2026

Creating liberating content

Bitcoin just slept through...

Bitcoin's leverage gauges barely flinched after Friday's Bank of Japan decision. A yen...

Why 110 corporate blockchains...

Corporate blockchains are multiplying, but Coinbase CEO Brian Armstrong expects the boom to...

Coldcard Wallet Flaw Exposes...

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is...

Coinbase spent 5 years...

Coinbase told investors on Thursday that 88% of its second-quarter net revenue came...

How a zeroed oracle signature unlocked $9M from Hedera DeFi lender Bonzo Lend

Hedera-based lending protocol Bonzo Lend has locked withdrawals after an oracle verifier accepted a proof containing a zeroed signature and public key, allowing a wallet to borrow $9.05 million against 250 SAUCE.

Bonzo Lend and Bonzo Points remained paused as of July 13, while the protocol’s official status page listed Bonzo Lend and all affected asset markets as under maintenance.

Liquidity providers remain unable to withdraw while Bonzo Finance Labs and the Bonzo Finance Foundation determine a recovery path and the conditions for reopening.

Wallet A first deposited 250 SAUCE, worth only a few dollars. At 00:51 UTC, it submitted a SAUCE/wHBAR price update that inflated the token’s value by roughly 12 orders of magnitude even though the market price stayed near 0.2 HBAR.

Eight seconds after the manipulated price reached the oracle’s on-chain storage, the wallet borrowed 6.63 million USDC.

It then borrowed 34.5 million wrapped HBAR, bringing the principal extracted by Wallet A to approximately $9.05 million at Bonzo’s reference prices.

Read More:  Crypto holders face a July 29 Maine deadline as state manual conflicts on when abandoned funds trigger seizure

Related Reading

How tokenized stocks fail as collateral even when the stock price does not move

Edel’s exploit was small, but it hit the next frontier for tokenized equities: credit markets, where 1:1 backing is not enough if wrappers, vaults and exchange rates can be gamed.

Jul 2, 2026 · Gino Matos

How zeros passed the verifier

The submitted update contained no valid oracle signature. Its signature field was [0,0], while the referenced committee public key was also the zero point, known in cryptography as the point at infinity.

Supra’s verifier sent those inputs to Hedera’s pairing precompile. Because both points represented the mathematical identity, the pairing equation returned true as designed.

The verifier then treated that result as proof of a committee signature because it had not first rejected zero, identity, and off-subgroup inputs.

In plain English, the network answered the equation it received correctly, while the verifier mistook that answer for authorization.