The DeFi protocol Bonzo Lend, operating within the Hedera ecosystem, fell victim to a sophisticated attack, resulting in the attacker draining assets worth approximately $9 million. The incident occurred due to the compromise of a third-party price oracle, allowing the hacker to manipulate market data in their favor.
According to a detailed analysis by the Bonzo Finance team, the attacker deposited only 250 SAUCE tokens as collateral. Subsequently, exploiting a vulnerability in the price verification system of the oracle provider Supra, the hacker submitted a fake asset price to the protocol, inflating it by approximately one trillion times. This colossal manipulation allowed them to borrow about 6.6 million USDC and 34.5 million wHBAR with virtually no collateral.

It is important to emphasize that the Bonzo Lend team linked the incident solely to an error in the price verification system of the oracle provider Supra, and not to flaws in the protocol's own smart contracts. After detecting the attack, the lending service and the points accrual program were immediately suspended.
The developers stated that they are actively cooperating with partners in the Hedera ecosystem to analyze the incident and prepare an asset recovery plan. Notably, one of the addresses involved in withdrawing about $1 million during the anomalous SAUCE price "window" identified itself as a "white hat hacker" and expressed an intention to return the funds.
As a reminder, in the first half of this year, crypto projects lost approximately $972 million across 207 incidents, according to Immunefi data. This case once again underscores the critical importance of oracle security—one of the most vulnerable links in DeFi infrastructure. Even the most reliable smart contracts are useless if the data they rely on can be compromised.