EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Bonzo Lend was attacked and lost $9 million, attackers manipulated the price of SAUCE oracle

2026-07-13 00:10:45
Bookmark

Bonzo Lend suffered an attack of approximately $9 million. The attacker manipulated the price of SAUCE oracle

Bonzo Lend, a decentralized lending protocol running on the Hedera network, suffered a serious security breach and lost approximately $9 million. The attack took advantage of flaws in the protocol oracle mechanism, allowing attackers to withdraw funds far beyond the actual value of the collateral.

The attacker used a oracle to boost the value of the collateral.

According to preliminary investigations, the attacker first only stored 250 units of SAUCE tokens (worth only a few dollars). Subsequently, the attacker submitted a tampered price update that magnified SAUCE's value by approximately 12 orders of magnitude. With this inflated value, the attacker lent 6.63 million USDC and 34.5 million encapsulated HBAR from Bonzo's loan pool. The manipulation targeted the agreement's reliance on on-chain pricing data, turning small collateral into a tool to extract millions of dollars from its liquidity pool.

Small Dictionary: In blockchain and DeFi, Oracle is a system that provides external data (such as asset prices) to smart contracts, allowing them to implement automated functions.

Bonzo Finance attributed the vulnerability to a flaw in the oracle verifier on the Supra chain that allows manipulated SAUCE price updates to be submitted via zero-signature. Supra, which supplied the affected oracle, has admitted the problem and implemented a fix.

Protocol and network have not been directly breached

Bonzo Finance said the attack did not stem from a vulnerability in its own smart contract or the underlying Hedera network, but a problem with the way the protocol oracle system verifies external price data, ultimately making it vulnerable to manipulation.

Bonzo is a decentralized finance (DeFi) lending protocol designed to allow users to provide assets as collateral and make loans on the Hedera blockchain. Hedera is a public distributed ledger platform focused on fast, secure and decentralized applications.

DeFi protocol faces increasing security threats

This attack has intensified the number of attacks on the DeFi protocol in 2026. A record 83 attacks occurred in the second quarter, with a total of approximately $755 million in stolen funds. Among them, cross-chain bridge attacks caused US$351 million in losses, while attacks involving breach of administrator rights and manipulation of token prices accounted for 37% of the total quarterly losses.

Category: Loss in the second quarter of 2026
Cross-chain bridge attack: US$351 million
Administrator rights breaches and price manipulation: accounted for 37% of total losses
DeFi total attack incidents: US$755 million (83 starts)

Overall, according to research firm CryptoRank, DeFi's total locked position value (TVL) fell 39% in 2026, from approximately US$115 billion in January to more than US$70 billion in June. The agency reported 121 hacking incidents and estimated losses of $942 million during this period, indicating that recurring security incidents continue to undermine user trust and lead to financial outflows.

Similar incidents in DeFi

The Bonzo Lend attack follows a similar attack on the YieldBlox DAO lending pool on Stellar's network earlier this year. In the incident, the attacker manipulated the price path used to evaluate UTRY collateral and stole approximately $10 million after borrowing assets that exceeded the actual value of the token.

These incidents highlight the continuing challenges associated with price oracles and external data sources in decentralized financial systems, areas that remain targets of complex attacks despite advances in smart contract security and blockchain infrastructure.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP