Bonzo Lend Suffers $9M Loss from Oracle Exploit on Hedera
Article Content
- •Bonzo Lend lost approximately $9 million due to an oracle exploit on July 11, 2026.
- •The attacker manipulated the SAUCE token price through a vulnerability in the Supra oracle's verification process.
- •Bonzo Lend has paused operations to assess the impact and develop recovery measures.
On July 11, 2026, Bonzo Lend, a decentralized lending protocol on the Hedera network, experienced a significant security breach resulting in losses of approximately $9 million. An attacker exploited a vulnerability in the third-party oracle provider, Supra, which allowed them to manipulate the price of the SAUCE token. By submitting an inflated price update, the attacker was able to borrow 6.63 million USDC and 34.5 million wrapped HBAR, far exceeding the actual value of their collateral. The exploit stemmed from a flaw in the oracle's signature verification process, which accepted a manipulated price without a valid signature. Bonzo Lend has since paused operations to assess the situation and develop recovery measures. The incident highlights the risks associated with reliance on external oracle systems in decentralized finance. A second account also borrowed funds during the exploit but later identified itself as a white-hat hacker intending to return the assets. Bonzo Finance Labs and the Bonzo Finance Foundation are coordinating recovery efforts and have confirmed that the incident did not originate from vulnerabilities within Bonzo Lend's contracts or the Hedera network.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (29)
Following this threat?
Track Bonzo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…