Bonzo Lend loses $9M in oracle exploit on Hedera
An attacker inflated the value of SAUCE collateral and borrowed $9 million from Bonzo Lend through a flaw in Supra’s on-chain oracle verifier.
Bonzo Lend, a decentralized lending protocol operating on the Hedera network, suffered a significant security breach resulting in approximately $9 million in losses. An attacker exploited a vulnerability in Supra's on-chain oracle verifier, manipulating the reported value of SAUCE token collateral. By artificially inflating the price of SAUCE, the exploiter was able to borrow funds far exceeding the actual collateral value, draining the protocol in the process.
Oracle exploits have become a recurring threat in decentralized finance, targeting the price-feed mechanisms that lending protocols rely on to assess collateral values. Supra's on-chain oracle verifier, which Bonzo Lend used to determine asset prices, contained a flaw that allowed the attacker to feed manipulated data into the system. Hedera, a distributed ledger network known for its hashgraph consensus model, has hosted a growing DeFi ecosystem, making it an increasingly attractive target for bad actors.
The incident highlights persistent vulnerabilities in DeFi infrastructure, particularly in oracle systems that serve as critical trust anchors for lending platforms. When oracle integrity is compromised, entire lending markets can be drained rapidly, often before protocol teams have time to respond. The attack raises fresh questions about the security standards applied to on-chain oracle verifiers across the broader industry.
Observers will be watching for official post-mortems from both Bonzo Lend and Supra, as well as any recovery efforts or potential on-chain negotiations with the attacker.
Source: Cointelegraph