On-chain records indicate Supra Network patched the same oracle deployment on 11 other chains before the Hedera contract used by Bonzo Lend was exploited for roughly $9 million over the weekend.
Bonzo Lend said the oracle accepted an extreme mispricing of the attacker’s collateral asset, which let the attacker borrow funds far above the collateral’s real value. A white-hat hacker later extracted a further $1 million.
Bonzo Lend traced the exploit to a Supra oracle
The vulnerable oracle was built by blockchain infrastructure developer Supra Network, which says its oracles are “live on 67 mainnets.”
Shortly after the exploit, Plasma’s Usmann Khan said Supra had upgraded many oracle deployments in the days leading up to the attack but had not updated the Hedera contract that Bonzo Lend relied on.
In a post on X, Khan wrote: “rough one. looks like @SUPRA_Labs actually knew about this exploit in their oracle. on more important networks like Arbitrum they upgraded their impls over the last 2wks (previously untouched for years). someone must have noticed this and found the forgotten Hedera instance.”
Supra’s report called it a “cryptographic edge case”
About 12 hours after the attack, Supra published an incident report describing the bug as a “cryptographic edge case.” The report did not mention that deployments on other chains had already been fixed.
It said only: “We have also reviewed every other Supra oracle deployment that shares this verifier pattern to confirm the same guards are in place.”
Supra co-founder and CEO Josh Tobkin said “AI-assisted hacking” had discovered what “human eyes had missed” for two years.
Tomachi Anura said the cross-chain fix had already been rolled out
After Khan’s post, HSuite founder Tomachi Anura examined Supra’s on-chain activity.

Anura said many people reported that @SUPRA_Labs patched its @hedera contracts only after the $9 million Bonzo hack. He said the on-chain record shows Supra shipped that exact fix to 11 chains in the days before Hedera was drained, then patched Hedera about six hours later.
According to Anura’s post, the company’s “cross-chain fix rollout” involved proxy upgrades on 11 chains between June 29 on Base and July 3 on Polygon. Two more fixes came after the exploit, on Hedera and Fuse.
Anura added that, while some upgrade addresses differ, “every one whose source is verified resolves to the same 17,354-char guarded SupraSValueFeedVerifier.”
Why the fixes stopped on July 3, leaving the Hedera deployment exposed, remains unclear. Protos said it has contacted Supra for clarification and will update the story if it receives a response.
Oracle failures have continued to produce losses
Third-party oracles are widely used by DeFi smart contracts to price assets and supply external data feeds. In attacks like this one, manipulated oracle prices can inflate the value of a collateral asset and drain available borrowing liquidity from lending platforms.
Protos said oracle exploits have caused another $3.5 million in losses in recent months.
It also pointed to another case in which the critical change to Moonwell’s “vibe-coded” oracle was co-authored by Claude. In a separate incident that was not strictly an exploit, a timestamp mismatch in Chaos Labs’ Correlated Asset Price Oracle led to $27 million worth of erroneous wstETH liquidations on Aave’s Ethereum markets in March.

