Crypto news

12.07.2026
08:36

The DeFi protocol Bonzo Lend on Hedera lost $9 million due to an oracle manipulation attack: the attacker inflated the token price by a trillion times.

The Hedera ecosystem has faced a serious security incident: the Bonzo Lend lending protocol was attacked, resulting in the loss of approximately $9 million in assets. According to internal investigation data, the root of the problem lies not in a vulnerability in the protocol's own smart contracts, but in the compromise of the third-party price oracle Supra.

The attack mechanism proved to be both simple and devastating. The attacker deposited 250 SAUCE tokens as collateral, then fed false price data for this asset to the oracle, artificially inflating it by approximately one trillion times. This allowed them to borrow about 6.6 million USDC and 34.5 million wHBAR with virtually zero real collateral. In essence, the attacker used a fake collateral valuation to instantly drain pool liquidity.

The Bonzo Finance team responded promptly to the incident, suspending the lending service and the points accrual program. In an official statement, the developers emphasized that the error occurred on the side of the oracle provider Supra, not in the protocol's code. Joint work is currently underway with partners in the Hedera ecosystem to analyze the situation and prepare a plan for recovering the funds.

Notably, one of the addresses involved in withdrawing approximately $1 million during the anomalous SAUCE price "window" identified itself as a "white hat hacker" and stated its intention to return the funds. This offers hope for partial compensation of the losses, although the overall picture remains uncertain.

Expert opinion: This incident is yet another reminder of the fundamental vulnerability of DeFi protocols that rely on external data sources. Even if smart contracts are flawless, a single point of failure in the form of an oracle can lead to catastrophic consequences. The market has long needed to reconsider security standards: either use decentralized oracles with multiple validation sources, or implement mechanisms to protect against price manipulation, such as dynamic loan limits during sharp spikes in collateral value. Otherwise, attacks like this, where trillion-fold multipliers become a reality, will continue to occur.