Attack on Bonzo Lend via Oracle: $9 million loss and a trillion-fold price surge for SAUCE

The DeFi protocol Bonzo Lend, operating within the Hedera ecosystem, fell victim to a targeted attack in which the attacker withdrew assets worth approximately $9 million. The key vulnerability was found not in the protocol's own smart contracts, but in the third-party price oracle provider Supra.
Price Manipulation: A Trillion-Fold Surge in SAUCE
According to my analysis of the incident, the attacker followed a classic oracle manipulation scheme. He deposited 250 SAUCE tokens as collateral, then fed fake data to the oracle, inflating the asset's price by approximately one trillion times. This allowed him to borrow about 6.6 million USDC and 34.5 million wHBAR with virtually zero collateral. In essence, the attacker created the illusion of a massive collateral that had no real value.
Team Response and Search for Those Responsible
The Bonzo Finance team promptly suspended the lending service and the points accrual program. Developers directly state that the incident is related to an error in the price verification system of the oracle provider Supra, not to flaws in the protocol's smart contracts. They are currently collaborating with partners in the Hedera ecosystem to analyze the incident and prepare an asset recovery plan.
Interesting twist: one of the addresses involved in withdrawing about $1 million during the anomalous SAUCE price "window" identified itself as a "white hat hacker" and stated its intention to return the funds. This could mitigate some of the losses, but does not negate the systemic problem.
Market Context
Let me remind you that in the first half of this year, crypto projects lost approximately $972 million as a result of 207 incidents. The attack on Bonzo Lend is another reminder that even reliable protocols can be compromised through infrastructure layers, such as oracles.
Expert Opinion: This case highlights the critical importance of decentralization and multiple data verification in oracles. Dependence on a single price data provider is a risk that can nullify all smart contract security efforts. Investors should pay attention to which oracles a protocol uses before providing liquidity.