← Back to News

Bonzo Lend Exploit: $9.05M Lost After Supra Oracle Verifier Bug on Hedera

07/12/2026 12:00
Bonzo Lend HackDeFi SecurityOracle Exploit

Hackers Keep Targeting DeFi: Bonzo Lend Loses $9.05M on Hedera

Decentralized lending protocol Bonzo Lend, built on the Hedera (HBAR) network, was hit by a cyberattack late Friday U.S. time, losing roughly $9.05 million in assets. According to Bonzo's initial report, the attacker exploited a vulnerability in Supra's third-party oracle verifier system to post a fake price for the SAUCE token.

Key takeaways:

  • An attacker exploited a bug in Supra's oracle verifier system to fake the price of SAUCE and borrow roughly $9.05 million from Bonzo Lend
  • Hedera confirmed the exploit was isolated to a third-party oracle service and did not affect the network's core infrastructure

This is another reminder that DeFi risk increasingly sits at the infrastructure layer, oracles, verifiers, and permissions, rather than in the core smart contracts themselves.

What Happened: Bonzo Lend Pauses Operations

According to The Block, Bonzo Lend suspended platform activity following the attack. Its points program was also paused, though vaults, the bridge, and staking products were unaffected. Hedera stated on X that the incident was limited to the third-party oracle verifier and that no flaw existed in the network's core infrastructure.

How the Exploit Worked

Around 8:40 PM U.S. time, the attacker deposited just 250 SAUCE tokens, worth only a few dollars as collateral. They then submitted a price update to Supra's request oracle contract, inflating the token's reported value by roughly 12 orders of magnitude. SAUCE was trading around 0.2 HBAR at the time, but the falsified price reflected a number 30 zeros larger.

Seconds later, at 8:51 PM, the same wallet borrowed approximately 6.63 million USDC and 34.5 million Wrapped HBAR against that now near-worthless collateral. Using an approximate HBAR price of $0.07, Bonzo estimated the total value drained at around $9.05 million.

Supra's verifier system should have rejected the price request, but a technical flaw in its signature verification process caused it to accept the update as valid instead. In simple terms, the attacker didn't break Supra's cryptography or steal its signing keys, they found a way to trick the verifier into treating an entirely invalid update as legitimate.

Bonzo said Supra confirmed the issue and deployed a patched version of the verifier contract to Hedera mainnet, which allowed the team to reconstruct exactly how the attack unfolded.

A Second Wallet and a White-Hat Twist

While the fake price was still active, a second wallet borrowed roughly $1 million using the same exploit. That wallet's owner then contacted the Bonzo team, identified themselves as a white-hat hacker, and said they intended to return the funds. As a result, Bonzo excluded this amount from its official damage estimate otherwise, total losses would have reached approximately $10.06 million.

Timeline of the Response

On-chain researcher Specter was reportedly the first to flag suspicious asset transfers from Hedera to Ethereum, which led Bonzo to confirm the attack's origin. The correct SAUCE price was restored via the oracle at 9:36 PM, and five minutes later, Bonzo paused its lending pool entirely.

Part of a Costly Year for DeFi Security

This exploit adds to what's already been a difficult year for crypto security. According to Immunefi, DeFi projects suffered roughly $972 million in losses across a record 207 attacks in just the first half of 2026.

The pattern is notable: attacks are increasingly targeting infrastructure oracle verifiers, private key compromises, and privileged access controls, rather than flaws in a protocol's core smart contract logic. For traders and liquidity providers, that shifts the due-diligence question from "is the contract audited" to "what third-party dependencies does this protocol rely on."

Get Full Access to All Our Content for Free!
You can find our other outlets at the bottom of the website.
Telegram