{"id":9233,"date":"2026-07-16T13:51:07","date_gmt":"2026-07-16T10:51:07","guid":{"rendered":"https:\/\/handoli.com\/index.php\/2026\/07\/16\/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit\/"},"modified":"2026-07-16T13:51:07","modified_gmt":"2026-07-16T10:51:07","slug":"supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit","status":"publish","type":"post","link":"https:\/\/handoli.com\/index.php\/2026\/07\/16\/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit\/","title":{"rendered":"Supra patched oracle on 11 other chains before $9M Hedera exploit"},"content":{"rendered":"<div><\/div>\n<p>A faulty oracle that caused a $9 million exploit over the weekend was patched on 11 chains in the days leading up to the attack, with the exploited Hedera deployment left vulnerable.<\/p>\n<p>The affected protocol, Bonzo Lend, <a href=\"https:\/\/bonzo.finance\/blog\/bonzo-lend-incident-report-oracle-provider-exploit\" target=\"_blank\" rel=\"noreferrer noopener\">explained<\/a> that the oracle accepted an extreme mispricing of the attacker\u2019s collateral asset, which allowed them to borrow funds far in excess of the collateral\u2019s true value. <\/p>\n<p>A further $1 million was extracted by a white-hat hacker.<\/p>\n<p>The vulnerable oracle was created by blockchain infrastructure developer Supra Network, which <a href=\"https:\/\/supra.com\/oracles-product\/\" target=\"_blank\" rel=\"noreferrer noopener\">boasts<\/a> oracles \u201clive on 67 mainnets.\u201d<\/p>\n<p>Shortly after the exploit, Plasma\u2019s Usmann Khan <a href=\"https:\/\/x.com\/usmannk\/status\/2076048963103567903\" target=\"_blank\" rel=\"noreferrer noopener\">noted<\/a> that Supra had upgraded many of its oracles in the days leading up to the exploit, but not the contract on Hedera, which Bonzo Lend used.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">rough one. looks like <a href=\"https:\/\/x.com\/SUPRA_Labs?ref_src=twsrc%5Etfw\">@SUPRA_Labs<\/a> actually knew about this exploit in their oracle. on more important networks like Arbitrum they upgraded their impls over the last 2wks (previously untouched for years). someone must have noticed this and found the forgotten Hedera instance <a href=\"https:\/\/t.co\/8Fk2ZL4WY1\">https:\/\/t.co\/8Fk2ZL4WY1<\/a> <a href=\"https:\/\/t.co\/GsyfORQExk\">pic.twitter.com\/GsyfORQExk<\/a><\/p>\n<p>\u2014 usmann (@usmannk) <a href=\"https:\/\/x.com\/usmannk\/status\/2076048963103567903?ref_src=twsrc%5Etfw\">July 11, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p><em>Read more: <\/em><a href=\"https:\/\/protos.com\/these-crypto-chains-raised-500m-but-generate-just-360-in-daily-fees-1\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>These crypto chains raised $500M but generate just $360 in daily fees<\/em><\/a><\/p>\n<p>In an <a href=\"https:\/\/supra.com\/news\/security-incident-report-hedera-pull-oracle-verifier\/\" target=\"_blank\" rel=\"noreferrer noopener\">incident report<\/a> published approximately 12 hours after the attack, Supra called the bug a \u201ccryptographic edge case\u201d and doesn\u2019t mention having fixed deployments on other chains.<\/p>\n<p>It simply states, \u201cWe have also reviewed every other Supra oracle deployment that shares this verifier pattern to confirm the same guards are in place.\u201d<\/p>\n<p>Supra\u2019s co-founder and CEO Josh Tobkin <a href=\"https:\/\/x.com\/JoshuaTobkin\/status\/2076630890017587515\" target=\"_blank\" rel=\"noreferrer noopener\">blamed<\/a> \u201cAI-assisted hacking\u201d for discovering \u201cwhat human eyes had missed\u201d for two years.<\/p>\n<h2 class=\"wp-block-heading\">Patching the bug<\/h2>\n<p>However, following Khan\u2019s post, HSuite founder Tomachi Anura <a href=\"https:\/\/x.com\/TomachiAnura\/status\/2077007819912405116\" target=\"_blank\" rel=\"noreferrer noopener\">analysed<\/a> Supra\u2019s on-chain activity.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Everyone reported <a href=\"https:\/\/x.com\/SUPRA_Labs?ref_src=twsrc%5Etfw\">@SUPRA_Labs<\/a> patched their <a href=\"https:\/\/x.com\/hedera?ref_src=twsrc%5Etfw\">@hedera<\/a> contracts AFTER the $9M Bonzo hack.<\/p>\n<p>The on-chain record shows <a href=\"https:\/\/x.com\/SUPRA_Labs?ref_src=twsrc%5Etfw\">@SUPRA_Labs<\/a> shipped that exact fix to 11 chains days before Hedera was drained \u2014 and patched Hedera ~6h after.<\/p>\n<p>I&#8217;ve been digging deep, and presenting pure facts as\u2026 <a href=\"https:\/\/t.co\/n72jwQZdDl\">https:\/\/t.co\/n72jwQZdDl<\/a><\/p>\n<p>\u2014 Tomachi Anura (@TomachiAnura) <a href=\"https:\/\/x.com\/TomachiAnura\/status\/2077008748279689554?ref_src=twsrc%5Etfw\">July 14, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p><em>Read more: <\/em><a href=\"https:\/\/protos.com\/cap-stabledrop-u-turn-sees-cusd-drop-23m-founder-denies-self-dealing-claims\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Cap \u2018stabledrop\u2019 U-turn sees cUSD drop $23M, founder denies self dealing claims<\/em><\/a><\/p>\n<p>Anura\u2019s post details the firm\u2019s \u201ccross-chain fix rollout\u201d, with proxy upgrades on 11 chains between June 29 (<a href=\"https:\/\/basescan.org\/tx\/0x2e2e711ffce0fb8076eb396b96d7014468b24a3f3100e0b7eece8639f066c49e\" target=\"_blank\" rel=\"noreferrer noopener\">Base<\/a>) and July 3 (<a href=\"https:\/\/polygonscan.com\/tx\/0x1090e0f5bcd6bbbf223a065e8fb9ac3429a38341162faf77fd1a8516e3de1cd9\" target=\"_blank\" rel=\"noreferrer noopener\">Polygon<\/a>), with a further two fixes (on <a href=\"https:\/\/hashscan.io\/mainnet\/transaction\/0x3dd860ca18bccca63c0149c27be0862abeb8db00c78bf26fc97c13fa280fa8e7\" target=\"_blank\" rel=\"noreferrer noopener\">Hedera<\/a> and <a href=\"https:\/\/explorer.fuse.io\/tx\/0x28538ef958d08aa7fdc27123b2149dda194da1c5a2d7652af35c85361cafb451\" target=\"_blank\" rel=\"noreferrer noopener\">Fuse<\/a> taking place post-exploit). <\/p>\n<p>Anura insists that, while some upgrade addresses vary, \u201cevery one whose source is verified resolves to the same 17,354-char guarded SupraSValueFeedVerifier.\u201d<\/p>\n<p>It remains unclear why the fixes stopped on July 3, leaving the Hedera deployment vulnerable.<\/p>\n<p>Protos has reached out to Supra for clarification, and will update this article should we hear back.<\/p>\n<p><em>Read more: <\/em><a href=\"https:\/\/protos.com\/oracle-error-adds-to-turmoil-at-defi-giant-aave\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Oracle error adds to turmoil at DeFi giant Aave<\/em><\/a><\/p>\n<h2 class=\"wp-block-heading\"><strong>Oracles\u2019 costly misfires<\/strong><\/h2>\n<p>Third-party oracles are used by many DeFi projects\u2019 smart contracts to price assets, or for other external data feeds.<\/p>\n<p>Oracle manipulation attacks are commonly used, like in this case, to inflate the value of a collateral asset and drain available borrow liquidity on DeFi lending platforms.\u00a0<\/p>\n<p><a href=\"https:\/\/protos.com\/defi-exploiter-targets-lending-protocols-with-oracle-tricks\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle exploits<\/a> have led to a further $3.5 million in losses in recent months. In <a href=\"https:\/\/protos.com\/defi-meet-claude-moonwells-vibe-coded-oracle-in-1-8m-blowup\/\" target=\"_blank\" rel=\"noreferrer noopener\">one incident<\/a>, the critical change to Moonwell\u2019s \u201cvibe-coded\u201d oracle was co-authored by Claude.<\/p>\n<p>While not strictly an exploit, a timestamp mismatch error in Chaos Labs\u2019 Correlated Asset Price Oracle led to a <a href=\"https:\/\/protos.com\/oracle-error-adds-to-turmoil-at-defi-giant-aave\/\" target=\"_blank\" rel=\"noreferrer noopener\">staggering $27 million<\/a> worth of erroneous wstETH liquidations on Aave\u2019s Ethereum markets in March.<\/p>\n<p><em>Got a tip? Send us an email securely via\u00a0<a href=\"https:\/\/leaks.protos.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Protos Leaks<\/em><\/a>. For more informed news and investigations, follow us on\u00a0<a href=\"https:\/\/twitter.com\/protos\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>,\u00a0<a href=\"https:\/\/bsky.app\/profile\/protos.com\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Bluesky<\/em><\/a>, and\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqJAgKIh5DQklTRUFnTWFnd0tDbkJ5YjNSdmN5NWpiMjBvQUFQAQ\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Google News<\/em><\/a>, or subscribe to our\u00a0<a href=\"https:\/\/youtube.com\/protosmedia\" target=\"_blank\" rel=\"noreferrer noopener\"><em>YouTube<\/em><\/a>\u00a0channel.<\/em><\/p>\n<p>The post <a href=\"https:\/\/protos.com\/supra-patched-oracle-on-11-other-chains-before-9m-hedera-exploit\/\">Supra patched oracle on 11 other chains before $9M Hedera exploit<\/a> appeared first on <a href=\"https:\/\/protos.com\/\">Protos<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>A faulty oracle that caused a $9 million exploit over the weekend was patched on 11 chains in the days leading up to the attack, with the exploited Hedera deployment left vulnerable. The affected protocol, Bonzo Lend, explained that the oracle accepted an extreme mispricing of the attacker\u2019s collateral asset, which allowed them to borrow [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9234,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[147],"tags":[],"class_list":["post-9233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-invest"],"_links":{"self":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/comments?post=9233"}],"version-history":[{"count":0,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9233\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media\/9234"}],"wp:attachment":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media?parent=9233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/categories?post=9233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/tags?post=9233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}