Bonzo Lend, a lending protocol on Hedera, lost about $9.05 million after an attacker exploited a flaw tied to a third-party oracle contract on July 11. The incident centered on a bad price update for SAUCE that allowed a small amount of collateral to be treated as far more valuable than it was, enabling large borrows before the protocol was halted.

How the exploit worked

According to a preliminary incident report, the attacker deposited 250 SAUCE tokens as collateral, an amount worth only a few dollars. The attacker then submitted a manipulated oracle price update that sharply inflated the token’s value against HBAR.

With the distorted collateral value in place, the account borrowed 6.63 million USDC and 34.52 million wrapped HBAR. Using the report’s reference price for HBAR, those assets were worth roughly $9.05 million.

The pricing failure was linked to Supra’s oracle infrastructure on Hedera rather than Bonzo’s internal lending logic. Bonzo said the issue stemmed from a verification flaw in a third-party Supra oracle contract.

Second wallet and white-hat claim

A second wallet also borrowed funds while the abnormal price remained active. That wallet took roughly $1 million more, bringing total abnormal borrowing to about $10.06 million before any recovery.

Bonzo said the second wallet later contacted the protocol through Discord, identified itself as a white-hat responder, and said the funds would be returned. The source article does not say whether that return had been completed.

Bonzo’s public updates and protocol status

During the incident, Bonzo’s X account said the lending protocol had been temporarily paused while the team investigated what it first described as volatile markets. It later confirmed that the protocol remains paused as recovery work continues.

That pause leaves the platform in a recovery phase while teams assess losses and the path forward. No timeline for reopening was provided in the source material.

Supra’s explanation and market impact

Supra Labs published its own incident report and attributed the failure to what it described as a degenerate BLS signature and a zero-valued public key that its Hedera verifier incorrectly accepted. Supra said the problem affected a single SAUCE/wHBAR feed and that its core aggregation systems and other feeds were not impacted.

The fallout spread beyond Bonzo. Hedera’s total value locked dropped nearly 40% over 24 hours after the exploit, while Bonzo’s own TVL fell 77% over the same period. DefiLlama data cited in the report showed Bonzo’s TVL at around $3.06 million.

A technical writeup by a security researcher also said that more than $5.25 million of the stolen funds was bridged to Ethereum through LayerZero and swapped into ETH within hours.

The incident adds to a familiar DeFi risk pattern in which manipulated or invalid oracle data can undermine lending markets even when the core borrowing system itself is not directly breached. In this case, the known facts point to a single corrupted feed on Hedera, a protocol pause at Bonzo, and an unresolved recovery process following more than $10 million in abnormal borrowing.

Source: thedefiant.io