Home
/
Blockchain technology
/
Decentralized applications
/

$9 m drain from hedera's bonzo lend: oracle flaw exposed

$9M Drain from Hedera's Bonzo Lend | Oracle Flaw Sparks Security Concerns

By

Nina Patel

Jul 12, 2026, 04:03 PM

Edited By

Elena Ivanova

Updated

Jul 12, 2026, 09:50 PM

2 minutes reading time

A hacker manipulating a digital interface to exploit a flaw in Hedera's Bonzo Lend lending protocol, representing a security breach leading to a $9M theft.

A major security breach involving Bonzo Lend has left the crypto community rattled. An attacker exploited a flaw in a third-party oracle system on July 11, 2026, draining nearly $9 million from the platform. This incident raises serious concerns about the integrity of decentralized finance frameworks.

Understanding the Attack

The attack occurred when an entity using Wallet A deposited just 250 SAUCE tokens and then manipulated price data provided by the Supra oracle. By inserting a drastically inflated value, the attacker tricked the system into approving a massive withdrawal. According to Bonzo Finance Labs, "The verifier trusted a correct answer to the wrong question."

This flaw lies within the oracle's verification process, which failed to reject a zeroed signature from Wallet A. As a result, Bonzo's contracts operated as intended, allowing the unauthorized borrower to liquidate 6,634,528 USDC and 34,518,389 wHBAR.

"Why not use Chainlink?" read one comment, highlighting doubts about the choice of oracle. Another user questioned the platform's risk controls, stating,

"Bonzo still does not get a free pass. Its risk controls need to be examined."

Additional Insights and Community Sentiment

Further investigation revealed that while Wallet A caused the significant loss, Wallet B also exploited the same vulnerability. This account borrowed nearly $1 million before the error was corrected but later contacted the Bonzo team, describing themselves as a white-hat responder willing to return the funds.

Community responses have underscored dissatisfaction with the situation:

  • "What a letdown. This is a black mark on the ecosystem."

  • "Should probably have Oracle redundancy and use all 3 (Chainlink, Pyth, Supra)."

  • "Seems like an obvious attack vector."

The Aftermath and Future Steps

In response to the incident, Bonzo Lend has paused its lending protocol while other services remain operational. The team is collaborating with Supra, which has acknowledged the flaw and patched their verifier on the Hedera network.

Looking Ahead

The consequences of this breach are expected to bring changes across the industry. Experts believe that many platforms will reassess their reliance on third-party oracles, likely shifting to in-house solutions or stronger partnerships with trusted providers.

Key Takeaways

  • 馃攳 The attack exploited flaws in the third-party oracle system used by Bonzo Lend.

  • 鈿狅笍 "Every price written to the Supra feed must carry a valid BLS signature," showing the need for stronger verification.

  • 馃挕 Wallet B's willingness to return the funds highlights potential for positive actions post-breach.

Investigations are ongoing as Bonzo Finance Labs and ecosystem partners strategize recovery efforts to prevent future incidents. The importance of oracle integrity in decentralized finance is being reinforced, reminding all participants that trust is crucial for the ecosystem's health.