πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
DeFi

Bonzo Lend Loses $9.05M to a Flaw in a Price Oracle

11 Jul 2026by CryptoJazz Admin1 min read125 views
Bonzo Lend Loses $9.05M to a Flaw in a Price Oracle

Bonzo Lend, a lending market built on the Hedera network, lost $9.05 million on July 11 after an attacker exploited a verification flaw in a price oracle contract supplied by Supra, an outside data provider. The attacker deposited 250 low-value SAUCE tokens, pushed through manipulated price updates that inflated the reported value of that deposit, and borrowed against the inflated figure. Bonzo paused the protocol and published a preliminary incident report documenting the attacker's methodology and the movement of assets. Its account places the root cause in a third-party contract, not in its own code. The damage spread past the protocol itself: Bonzo's total value locked fell 77% within 24 hours, and Hedera's network-wide total fell nearly 40% to $25.7 million by CoinDesk's count.

250 SAUCE tokens and a price the contract believed

A lending market cannot see prices on its own. It takes deposits, lends against them, and to decide how much a borrower may withdraw it has to know what the pledged collateral is worth at that moment. That job is handed to an oracle, a contract whose only purpose is to publish outside price data on-chain so other contracts can read it. Every borrowing limit on Bonzo was derived from what the Supra oracle reported, which meant the honesty of the whole market rested on the honesty of that one feed.

The flaw sat in verification. The Supra contract accepted price updates it should have rejected, so a deposit of 250 SAUCE tokens, worth very little, could be made to read as collateral worth millions. After that, no further trickery was needed. The attacker simply borrowed against the inflated number and kept the proceeds, which were the assets other users had supplied to the pool. The failure shape matches a contract that trusted input it never verified on Secret Network's Axelar bridge in June, where forged cross-chain packets minted tokens nothing was backing.

77% of Bonzo's deposits, 40% of Hedera's

Total value locked, the sum of assets sitting inside a protocol, falls both when assets are taken and when remaining depositors pull theirs out, and Bonzo's dropped 77% in a single day. Hedera's network-wide total went with it, down nearly 40% to $25.7 million, a measure of how much of a smaller chain's activity can rest on one venue. The headline $9.05 million covers borrowed principal from the primary attacker. A second wallet borrowed roughly $1 million more using the same flaw, putting total assets borrowed at about $10.06 million before any recovery.

A pause, a report and a message on Discord

Bonzo halted the protocol once the pattern was clear, and it put the preliminary report out rather than waiting for a full postmortem. The second wallet then contacted the team on Discord, identifying itself as a white-hat responder, someone who front-runs or copies an attack to hold the funds safe, and signaled it intended to return the roughly $1 million it had taken. Bonzo excluded the sum on that basis. The primary $9.05 million had not been recovered as of Saturday.

A dependency Bonzo did not write

Bonzo's own contracts were not broken. That is the uncomfortable part. The protocol was undone by a component it read from, and that leaves a question no code review of its own repository can answer: what else does it trust, and who checks that. It is the recurring shape of the year's largest thefts, where the broken piece has repeatedly sat beside the lending logic instead of inside it. In June it was a set of multisig keys meant for four separate people that had been backed up to a single compromised laptop. Still open on July 11: whether the white-hat wallet returns the $1 million it signaled it would, and whether Supra publishes its own account of the verification flaw. Whether Hedera's deposits come back, or stay where the pause left them, is a slower question.

Read also: Injective's npm SDK Was Backdoored to Steal Seed Phrases

← All news