The Hedera ecosystem has suffered a major blow: the DeFi protocol Bonzo Lend fell victim to an attack, resulting in the attacker draining approximately $9 million in assets. The key cause of the incident was the compromise of a third-party price oracle, not a vulnerability in the protocol's own smart contracts.
A detailed analysis shows that the attacker deposited only 250 SAUCE tokens as collateral. Then, exploiting a breach in the verification system of the Supra oracle provider, they submitted a fake asset price, inflating it by roughly a trillion times. This allowed them to borrow approximately 6.6 million USDC and 34.5 million wHBAR with virtually no collateral. Essentially, the oracle manipulation created a fictitious collateral value sufficient to drain massive liquidity.
Immediately after detecting the attack, the Bonzo Lend team suspended the lending service and the points accrual program. The developers emphasize that they are cooperating with partners in the Hedera ecosystem to analyze the incident and prepare an asset recovery plan.
Notably, one of the addresses involved in withdrawing about $1 million during the SAUCE price anomaly "window" identified itself as a "white hat hacker" and stated its intention to return the funds. This indicates the possible presence of ethical hackers who acted within the scope of the attack but are willing to cooperate.
This incident once again highlights the critical vulnerability of DeFi protocols that rely on third-party oracles. Even flawless smart contracts are useless if the data source they depend on can be compromised. Against the backdrop of crypto projects losing approximately $972 million in 207 incidents in the first half of the year, according to Immunefi, the attack on Bonzo Lend serves as another reminder of the need for multi-layered security and decentralized oracles.
My expert conclusion: The attack on Bonzo Lend is a classic example of how one weak element in the infrastructure can bring down an entire system. Protocols need not only to thoroughly audit their own contracts but also to conduct deep security analysis of the data providers they rely on. Otherwise, such incidents will recur, undermining trust in DeFi as a whole.