Hedera lending platform Bonzo Lend suffers nine million dollar loss after oracle exploit

Share

Bonzo Lend, a decentralized lending protocol built on the Hedera mainnet, announced an emergency pause to its operations after a sophisticated oracle exploit resulted in an estimated loss of $9.05 million. The incident, which unfolded on July 11 2026, highlights the persistent challenges of securing price feeds in the rapidly evolving DeFi ecosystem and underscores the importance of rigorous verification layers for third‑party oracles.

According to the detailed incident report released by the Bonzo team, the attack began at approximately 00:51 UTC when an address identified as Wallet A submitted a manipulated price update for the SAUCE/wHBAR pair to a Hedera on‑demand oracle. The price submitted was dramatically higher than the prevailing market rate, a discrepancy that the protocol’s pricing engine accepted as valid collateral value. Within seconds the attacker used a minimal amount of SAUCE as collateral to borrow assets valued far beyond the true worth of the supplied token, effectively siphoning the protocol of millions of dollars.

The root cause of the exploit lies in the signature verification stage of the oracle contract. Bonzo Lend relies on a hybrid oracle model that incorporates both Supra and Chainlink feeds, with the majority of asset prices delivered via Supra’s push model. In this architecture, Supra’s oracle committee signs price data off‑chain and pushes the signed payload onto Hedera, while Bonzo Lend simply reads the stored price to assess loan‑to‑value ratios. The report clarifies that no forged signatures were involved and that the market price of SAUCE remained stable throughout the attack window.

Instead, the vulnerability stemmed from an incomplete validation check. The data transmitted by Wallet A contained a committee identifier, a committee hash, and a signature field that was deliberately set to zero. A robust verifier should have rejected the submission at the earliest stage, before any cryptographic pairing operation was invoked. However, the contract passed the malformed payload to Hedera’s BLS pairing pre‑compile. Because both the signature point and the referenced public key were zeroed, the mathematical pairing check returned a true result, leading the system to accept the price update as authentic despite its lack of contextual validity.

Bonzo Lend emphasizes that the breach was not a flash‑loan attack, nor was it a conventional market manipulation scheme. The protocol’s core contracts performed exactly as coded; the fault originated in the oracle’s verification logic, a component external to the lending platform’s primary codebase. This distinction is critical for stakeholders assessing liability and for developers designing future oracle integrations on Hedera.

The financial impact of the exploit is calculated based on the principal withdrawn by the attacker, amounting to roughly $9.05 million. This figure excludes accrued interest, transaction fees, subsequent market fluctuations, and any assets that may be recovered through forensic investigation. The protocol’s emergency pause will remain in effect while the team collaborates with security auditors and Hedera developers to remediate the verification flaw and to reinforce the resilience of its oracle pipeline.

Industry observers note that this incident serves as a cautionary tale for projects that depend on external price feeds. While Hedera’s high‑throughput architecture offers attractive performance characteristics for DeFi applications, the security of oracle inputs remains a pivotal factor in safeguarding user funds. Implementing multi‑layer signature checks, redundant price sources, and on‑chain fallback mechanisms are emerging best practices that could mitigate similar risks.

Looking ahead, Bonzo Lend plans to introduce stricter validation rules, including mandatory non‑zero signatures and additional sanity checks on price deviation thresholds. The protocol also intends to diversify its oracle ecosystem by integrating more decentralized feed providers, thereby reducing reliance on a single data source. These steps aim to restore confidence among lenders and borrowers while reinforcing the broader Hedera DeFi landscape.

Alexandra Solorio
Alexandra joined DefiSources.com after years of trading and yield farming across Ethereum and Solana. Now she writes about the markets she used to trade, bringing firsthand experience to her coverage of DeFi protocols, NFT ecosystems, and the latest meme coin cycles.

Table of contents [hide]

Read more

Local News