Hackers Keep Targeting DeFi: Bonzo Lend Loses $9.05M on Hedera
Decentralized lending protocol Bonzo Lend, built on the Hedera (HBAR) network, was hit by a cyberattack late Friday U.S. time, losing roughly $9.05 million in assets. According to Bonzo's initial report, the attacker exploited a vulnerability in Supra's third-party oracle verifier system to post a fake price for the SAUCE token.
Key takeaways:
- An attacker exploited a bug in Supra's oracle verifier system to fake the price of SAUCE and borrow roughly $9.05 million from Bonzo Lend
- Hedera confirmed the exploit was isolated to a third-party oracle service and did not affect the network's core infrastructure
This is another reminder that DeFi risk increasingly sits at the infrastructure layer, oracles, verifiers, and permissions, rather than in the core smart contracts themselves.
What Happened: Bonzo Lend Pauses Operations
According to The Block, Bonzo Lend suspended platform activity following the attack. Its points program was also paused, though vaults, the bridge, and staking products were unaffected. Hedera stated on X that the incident was limited to the third-party oracle verifier and that no flaw existed in the network's core infrastructure.
How the Exploit Worked
Around 8:40 PM U.S. time, the attacker deposited just 250 SAUCE tokens, worth only a few dollars as collateral. They then submitted a price update to Supra's request oracle contract, inflating the token's reported value by roughly 12 orders of magnitude. SAUCE was trading around 0.2 HBAR at the time, but the falsified price reflected a number 30 zeros larger.
Seconds later, at 8:51 PM, the same wallet borrowed approximately 6.63 million USDC and 34.5 million Wrapped HBAR against that now near-worthless collateral. Using an approximate HBAR price of $0.07, Bonzo estimated the total value drained at around $9.05 million.
Supra's verifier system should have rejected the price request, but a technical flaw in its signature verification process caused it to accept the update as valid instead. In simple terms, the attacker didn't break Supra's cryptography or steal its signing keys, they found a way to trick the verifier into treating an entirely invalid update as legitimate.
Bonzo said Supra confirmed the issue and deployed a patched version of the verifier contract to Hedera mainnet, which allowed the team to reconstruct exactly how the attack unfolded.
A Second Wallet and a White-Hat Twist
While the fake price was still active, a second wallet borrowed roughly $1 million using the same exploit. That wallet's owner then contacted the Bonzo team, identified themselves as a white-hat hacker, and said they intended to return the funds. As a result, Bonzo excluded this amount from its official damage estimate otherwise, total losses would have reached approximately $10.06 million.
Timeline of the Response
On-chain researcher Specter was reportedly the first to flag suspicious asset transfers from Hedera to Ethereum, which led Bonzo to confirm the attack's origin. The correct SAUCE price was restored via the oracle at 9:36 PM, and five minutes later, Bonzo paused its lending pool entirely.

Part of a Costly Year for DeFi Security
This exploit adds to what's already been a difficult year for crypto security. According to Immunefi, DeFi projects suffered roughly $972 million in losses across a record 207 attacks in just the first half of 2026.
The pattern is notable: attacks are increasingly targeting infrastructure oracle verifiers, private key compromises, and privileged access controls, rather than flaws in a protocol's core smart contract logic. For traders and liquidity providers, that shifts the due-diligence question from "is the contract audited" to "what third-party dependencies does this protocol rely on."
