Supra patched the same oracle on 11 chains before the $9 million Hedera exploit

Supra patched the same oracle on 11 chains before the $9 million Hedera exploit

N
News Editor
2026-07-15 16:23:14
On-chain activity reviewed after the Bonzo Lend exploit suggests Supra Network had already rolled out the same oracle fix across 11 other chains before the vulnerable Hedera deployment was updated. Bonzo Lend said the oracle accepted an extreme mispricing of the attacker’s collateral asset, allowing the attacker to borrow far more than the collateral was actually worth. Roughly $9 million was taken in the weekend exploit, and another $1 million was later extracted by a white-hat hacker. The oracle came from Supra, which says its feeds are live on 67 mainnets. After the attack, Plasma’s Usmann Khan said Supra had upgraded several oracle implementations in the days before the exploit but had not updated the Hedera contract Bonzo Lend relied on. HSuite founder Tomachi Anura later said on-chain records show proxy upgrades on 11 chains from June 29 through July 3, with Hedera and Fuse patched only after the exploit. Supra’s incident report described the bug as a “cryptographic edge case,” while co-founder and CEO Josh Tobkin said “AI-assisted hacking” had found what “human eyes had missed” for two years. Protos said it has asked Supra for clarification.
Supra NetworkHederaBonzo LendoracleDeFi lendingon-chain analysisexploit

On-chain records indicate Supra Network patched the same oracle deployment on 11 other chains before the Hedera contract used by Bonzo Lend was exploited for roughly $9 million over the weekend.

Bonzo Lend said the oracle accepted an extreme mispricing of the attacker’s collateral asset, which let the attacker borrow funds far above the collateral’s real value. A white-hat hacker later extracted a further $1 million.

Bonzo Lend traced the exploit to a Supra oracle

The vulnerable oracle was built by blockchain infrastructure developer Supra Network, which says its oracles are “live on 67 mainnets.”

Shortly after the exploit, Plasma’s Usmann Khan said Supra had upgraded many oracle deployments in the days leading up to the attack but had not updated the Hedera contract that Bonzo Lend relied on.

In a post on X, Khan wrote: “rough one. looks like @SUPRA_Labs actually knew about this exploit in their oracle. on more important networks like Arbitrum they upgraded their impls over the last 2wks (previously untouched for years). someone must have noticed this and found the forgotten Hedera instance.”

Supra’s report called it a “cryptographic edge case”

About 12 hours after the attack, Supra published an incident report describing the bug as a “cryptographic edge case.” The report did not mention that deployments on other chains had already been fixed.

It said only: “We have also reviewed every other Supra oracle deployment that shares this verifier pattern to confirm the same guards are in place.”

Supra co-founder and CEO Josh Tobkin said “AI-assisted hacking” had discovered what “human eyes had missed” for two years.

Tomachi Anura said the cross-chain fix had already been rolled out

After Khan’s post, HSuite founder Tomachi Anura examined Supra’s on-chain activity.

Supra patched the same oracle on 11 chains before the $9 million Hedera exploit 3

Anura said many people reported that @SUPRA_Labs patched its @hedera contracts only after the $9 million Bonzo hack. He said the on-chain record shows Supra shipped that exact fix to 11 chains in the days before Hedera was drained, then patched Hedera about six hours later.

According to Anura’s post, the company’s “cross-chain fix rollout” involved proxy upgrades on 11 chains between June 29 on Base and July 3 on Polygon. Two more fixes came after the exploit, on Hedera and Fuse.

Anura added that, while some upgrade addresses differ, “every one whose source is verified resolves to the same 17,354-char guarded SupraSValueFeedVerifier.”

Why the fixes stopped on July 3, leaving the Hedera deployment exposed, remains unclear. Protos said it has contacted Supra for clarification and will update the story if it receives a response.

Oracle failures have continued to produce losses

Third-party oracles are widely used by DeFi smart contracts to price assets and supply external data feeds. In attacks like this one, manipulated oracle prices can inflate the value of a collateral asset and drain available borrowing liquidity from lending platforms.

Protos said oracle exploits have caused another $3.5 million in losses in recent months.

It also pointed to another case in which the critical change to Moonwell’s “vibe-coded” oracle was co-authored by Claude. In a separate incident that was not strictly an exploit, a timestamp mismatch in Chaos Labs’ Correlated Asset Price Oracle led to $27 million worth of erroneous wstETH liquidations on Aave’s Ethereum markets in March.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.