The DeFi protocol Bonzo Lend, deployed within the Hedera ecosystem, fell victim to a targeted attack, resulting in an attacker draining assets worth approximately $9 million. The key cause of the incident was the compromise of the third-party price oracle provider Supra, rather than a vulnerability in the protocol's own smart contracts.

How was the attack carried out?

According to an analysis conducted by the Bonzo Finance development team, the attacker executed a classic oracle manipulation scheme. They deposited only 250 SAUCE tokens as collateral. Subsequently, exploiting a vulnerability in Supra's price verification system, the hacker fed a fake asset price into the oracle, artificially inflating it by approximately one trillion times. This allowed them to borrow nearly 6.6 million USDC and 34.5 million wHBAR with virtually zero real collateral.

After the attack was detected, the Bonzo Lend lending service, as well as the points accrual program, were immediately suspended. The developers stated that they are actively cooperating with partners in the Hedera ecosystem to analyze the incident and prepare a plan for fund recovery.

Community reaction and a "white hat hacker"

Notably, one of the addresses involved in withdrawing approximately $1 million at the time of the anomalous SAUCE price change identified itself as a "white hat hacker." This participant communicated an intention to return the funds, which could partially mitigate the overall damage.

This incident once again underscores the critical importance of oracle security for DeFi. Even with flawless smart contracts, a vulnerability in a single external data source can lead to catastrophic losses. The price verification issues with Supra serve as a serious wake-up call for the entire Hedera ecosystem and the market at large. In the first half of this year, according to Immunefi, crypto projects lost approximately $972 million across 207 incidents, and this attack only adds to that alarming statistic.