The Hedera ecosystem has experienced another painful incident, vividly demonstrating how vulnerable DeFi protocols are to attacks on price oracles. The Bonzo Lend protocol fell victim to an attacker who managed to withdraw assets worth approximately $9 million. The key cause of the hack was the compromise of a third-party oracle data provider — Supra.

Attack Mechanics: Trillion-fold Price Inflation

According to my analysis of the Bonzo Finance team's report, the attacker acted elegantly and audaciously. He deposited only 250 SAUCE tokens as collateral. Then, exploiting a vulnerability in the Supra oracle's price verification system, the attacker submitted a fake asset price to the protocol, inflating it approximately one trillion times. This manipulation allowed him to borrow about 6.6 million USDC and 34.5 million wHBAR with virtually zero real collateral.

Team Response and the "White Hat Hacker"

After detecting the attack, Bonzo Lend developers immediately suspended the lending service and the points accrual program. They emphasized that the incident was related to an error in data verification by Supra, not bugs in the protocol's own smart contracts. The team is now cooperating with Hedera ecosystem partners to analyze the situation and develop an asset recovery plan.

Notably, one of the addresses involved in withdrawing about $1 million during the anomalous price "window" identified itself as a "white hat hacker" and stated its intention to return the funds. This adds intrigue to the investigation process.

Context: Crypto Industry Losses in 2026

This incident is just one of many in a series of attacks on crypto projects. According to Immunefi, in the first half of 2026, the crypto industry lost approximately $972 million as a result of 207 incidents. Oracle attacks remain one of the most dangerous vectors, as they undermine trust in the basic infrastructure of DeFi.

Expert Opinion: This hack is a classic example of how one weak element in the data supply chain can bring down an entire protocol. Projects need not only to rely on third-party oracles but also to implement redundancy mechanisms, price verification from multiple sources, and, critically, strict limits on maximum price changes per block. Without such safeguards, the DeFi sector will continue to lose millions to similar manipulations.