FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime and Investigations

Hedera DeFi Protocol Bonzo Lend Suffers $9M Oracle Attack

Hedera DeFi Protocol Bonzo Lend Suffers $9M Oracle Attack

A $9 million exploit at Bonzo Lend has renewed scrutiny of oracle infrastructure after investigators traced the attack to a third-party price verification flaw.

Summary:

  • Bonzo Lend lost approximately $9.05 million after attackers exploited a vulnerability in Supra’s oracle verification system.
  • The exploit manipulated the price of SAUCE tokens, allowing the attacker to borrow assets far exceeding the value of the posted collateral.
  • Bonzo Lend has paused the protocol, while Supra says the oracle flaw has been patched.
  • The incident did not affect Hedera’s underlying network, but highlights the growing security risks surrounding third-party oracle infrastructure.

Bonzo Lend Exploit Drains $9M Through Oracle Verification Flaw

Bonzo Lend, one of the largest decentralized lending protocols on the Hedera network, suspended operations after an attacker exploited a vulnerability in Supra’s on-chain oracle verification system, draining approximately $9.05 million in digital assets.

According to information from Yahoo Finance, the attacker stole roughly 6.63 million USDC and 34.5 million wrapped HBAR (WHBAR) by manipulating price data used to determine collateral values.

Oracle Verification Failure Enabled the Attack

The exploit originated from a flaw in Supra’s oracle verifier, rather than Bonzo Lend’s lending contracts or Hedera’s underlying blockchain.

The attacker deposited only 250 SAUCE tokens as collateral before submitting a manipulated oracle update that inflated the token’s reported price by approximately 12 orders of magnitude. Because the verifier failed to properly validate the oracle message – including accepting an update with an invalid or effectively zeroed signature – the protocol treated the collateral as vastly more valuable than it actually was.

That artificial collateral value allowed the attacker to borrow millions of dollars worth of assets before the manipulation was detected.

The incident illustrates how lending protocols remain dependent on external price feeds, where a single failure in oracle verification can compromise otherwise secure smart contracts.

Bonzo Lend Pauses Operations

Following the exploit, Bonzo Lend paused its protocol while the team investigates the incident and works with ecosystem partners on recovery efforts.

Supra acknowledged the vulnerability and said it has already deployed a fix to prevent the same verification flaw from being exploited again.

Both Bonzo Lend and Hedera emphasized that the attack did not originate from a vulnerability in Hedera’s consensus mechanism or the lending protocol’s core smart contracts. Instead, it stemmed from a failure in third-party infrastructure responsible for validating external market data.

That distinction matters because it limits the scope of the incident while highlighting the growing importance of oracle security across decentralized finance.

Oracle Risk Remains a Major DeFi Vulnerability

The exploit adds to a growing list of DeFi attacks in 2026 involving oracle infrastructure rather than blockchain consensus failures.

As lending protocols become increasingly interconnected with external data providers, security reviews are extending beyond smart contract code to include the reliability of price feeds, signature verification systems and other off-chain infrastructure.


READ MORE: Cardano Users Rush to Move Funds After Major Wallet Breach


For institutional participants, the incident reinforces that operational risk often extends beyond the blockchain itself. Even when the underlying network remains secure, vulnerabilities in third-party dependencies can expose protocols to significant losses.

HBAR Recovers After Sharp Selloff

HBAR initially fell sharply following reports of the exploit, dropping to roughly $0.0667 before recovering toward $0.0700 at the time of writing.

hedera price chart

The 15-minute chart shows buyers stepping in after the initial selloff, with price retracing most of the decline during the afternoon session. While the recovery suggests the market distinguished the oracle exploit from a network-level failure, HBAR remains below the intraday highs recorded before the incident, indicating traders continue to assess its broader implications.

What Investors Should Monitor Next

The next phase of the incident will likely focus on several key developments:

  • Recovery efforts: Whether Bonzo Lend can recover any of the stolen assets and compensate affected users.
  • Security reviews: Additional audits of Supra’s oracle infrastructure and other protocols relying on the same verification system.
  • Protocol reopening: The timeline for Bonzo Lend to resume lending operations after remediation.
  • Ecosystem confidence: Whether the exploit affects developer and user activity on Hedera or remains an isolated protocol-specific event.

While the attack resulted in significant losses, current evidence indicates it was an oracle infrastructure failure rather than a weakness in Hedera itself. That distinction is likely to shape both the market’s response and future security standards across the broader DeFi ecosystem.


The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.

Author
Alexander Stefanov - Editor-in-Chief at Coinspress
Alexander Stefanov

Reporter at CoinsPress

Alex is Editor-in-Chief of Coinspress and co-founder of Millennial Media Group, with nearly a decade of experience covering financial markets - crypto first, then everything else. It started in 2016 with Bitcoin. Like most people at the time, he didn't fully understand it - so he kept digging. Blockchain, tokenomics, the projects, the cycles. That curiosity never stopped, and eventually pulled him into traditional markets too: equities, commodities, macro. Not because he left crypto behind, but because you can't properly understand one without the other. What drives him is straightforward: he wants to know why something is happening, not just that it's happening. Most market coverage stops at the headline - price up, price down, here's a chart. Alex finds that kind of reporting actively unhelpful. If you walk away from an article without understanding the mechanism behind the move, what did you actually learn? He holds a degree in Tourism from New Bulgarian University - not the most obvious path into financial markets, but markets have a way of pulling in people who are simply too curious to stay out. He has authored over 200 in-depth analyses and more than 10,000 articles across crypto and traditional finance. He still thinks every day in markets teaches him something new. That's probably why he hasn't stopped.

Learn more about crypto and blockchain technology.

Glossary