Bonzo Finance says an attacker borrowed about $9 million from its Bonzo Lend pool on Hedera on July 11 after manipulating a third-party price oracle. The protocol said its own smart contracts were not breached, but it has paused Bonzo Lend and its points program while it investigates and works on recovery.

Attack traced to oracle feed

Initial reports described the incident as an exploit on the Hedera network. On-chain researcher Specter first tracked the funds as they moved to Ethereum, then later said the attack was tied to Bonzo Finance. The protocol subsequently confirmed the incident in its own report.

According to Bonzo Finance, the loss stemmed from a third-party SAUCE price oracle rather than a flaw in Bonzo Lend’s contracts. The team said it is investigating the event with partners and will continue to publish updates.

How the borrowing unfolded

Bonzo said the attacker deposited 250 SAUCE tokens as collateral. Those tokens were worth only a few dollars at the time, based on the protocol’s account of the incident. The attacker then manipulated the SAUCE price shown in the oracle feed, pushing it roughly 12 orders of magnitude above its real value.

With the inflated collateral valuation in place, the attacker was able to borrow large amounts from the lending pool within seconds. Bonzo said the address took out around 6.6 million USDC and 34.5 million Wrapped HBAR, or WHBAR, against the small deposit.

Bonzo’s statement indicates the exploit relied on distorted price data rather than unauthorized access to the protocol’s own contracts. That distinction is central to the project’s explanation of how the borrowing was possible.

Second wallet and response

A second wallet also borrowed about $1 million during the same period, according to the report. Bonzo said that wallet later identified itself as a white-hat responder and stated that it would return the funds.

The protocol has not presented the full recovery outcome so far, but said lending operations and its points program have been temporarily halted as recovery work continues. In a public message, the team said it was investigating volatile markets across Bonzo Lend and working alongside partners during the incident review.

Broader context

The episode highlights a familiar risk in on-chain lending: even when a protocol’s own contracts are not directly breached, bad price data from external infrastructure can still allow oversized borrowing. In this case, Bonzo Finance has attributed the roughly $9 million loss to oracle manipulation tied to SAUCE pricing on Hedera, while one additional borrower has claimed a white-hat role and said the funds will be returned.

Source: beincrypto.com