πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
DeFi

Bonzo Lend Loses $9.05M to a Flaw in a Price Oracle

11 Jul 2026by CryptoJazz Admin1 min read10 views
Bonzo Lend Loses $9.05M to a Flaw in a Price Oracle

Bonzo Lend, a lending market built on the Hedera network, lost $9.05 million on July 11 after an attacker exploited a verification flaw in a price oracle contract supplied by Supra, an outside data provider. The attacker deposited 250 low-value SAUCE tokens, submitted manipulated price updates that inflated the reported value of that deposit, and borrowed against the inflated figure. Bonzo paused the protocol and published a preliminary incident report documenting the attacker's methodology and the movement of assets, saying the root cause sat in a third-party contract rather than in its own code. The damage spread past the protocol itself: Bonzo's total value locked fell 77% within 24 hours, and Hedera's network-wide total fell nearly 40% to $25.7 million, according to CoinDesk.

The Mechanism: 250 SAUCE Tokens and a Price the Contract Believed

A lending market cannot see prices on its own. It takes deposits, lends against them, and to decide how much a borrower may withdraw it has to know what the pledged collateral is worth at that moment. That job is handed to an oracle β€” a contract whose only purpose is to publish outside price data on-chain so other contracts can read it. Every borrowing limit on Bonzo was derived from what the Supra oracle reported, which meant the honesty of the whole market rested on the honesty of that one feed.

The flaw was in verification. The Supra contract accepted price updates it should have rejected, so a deposit of 250 SAUCE tokens, worth very little, could be made to read as collateral worth millions. After that the theft needed no further trickery: the attacker simply borrowed against the inflated number and kept the proceeds, which were the assets other users had supplied to the pool. The failure shape matches a contract that trusted input it never verified on Secret Network's Axelar bridge in June, where forged cross-chain packets minted tokens nothing was backing.

The Damage: 77% of Bonzo's Deposits and 40% of Hedera's

Total value locked, the sum of assets sitting inside a protocol, is a figure that falls both when assets are taken and when remaining depositors pull theirs out, and Bonzo's dropped 77% in a single day. Hedera's network-wide total went with it, down nearly 40% to $25.7 million, a reminder of how much of a smaller chain's activity can rest on one venue. The headline $9.05 million covers borrowed principal from the primary attacker. A second wallet borrowed roughly $1 million more using the same flaw, putting total assets borrowed at about $10.06 million before any recovery.

The Response: A Pause, a Preliminary Report and a Message on Discord

Bonzo halted the protocol once the pattern was clear and put out the preliminary report rather than waiting for a full postmortem. The second wallet then contacted the team on Discord, identifying itself as a white-hat responder β€” someone who front-runs or copies an attack to hold the funds safe β€” and indicated it intended to return the roughly $1 million it had taken. Bonzo excluded that sum from its headline loss figure on that basis. The primary $9.05 million had not been recovered as of Saturday.

What Is Unresolved: A Dependency Bonzo Did Not Write

The uncomfortable part for Bonzo is that its own contracts were not broken. The protocol was undone by a component it read from, which leaves it with a question no code review of its own repository can answer: what else does it trust, and who checks that. It is the recurring shape of the year's largest thefts, where the broken piece has repeatedly sat beside the lending logic rather than inside it β€” in June, a set of multisig keys meant for four separate people that had been backed up to a single compromised laptop. Still open on July 11: whether the white-hat wallet returns the $1 million it signaled it would, whether Supra publishes its own account of the verification flaw, and whether Hedera's deposits come back or stay where the pause left them.

Read also: Injective's npm SDK Was Backdoored to Steal Seed Phrases

← All news