EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Bonzo Finance suffers a $9 million oracle attack at Hedera, TVL plunges 77%

2026-07-13 00:16:29
Bookmark

Bonzo Finance was attacked by a oracle bug, and TVL plunged 77%

Bonzo Finance, a lending agreement on the Hedera network, stole approximately US$9.05 million due to attackers exploiting verification flaws in third-party oracle contracts, causing its total locked position value (TVL) to plummet by 77%. This incident highlights the cascading risks that can arise when DeFi applications rely on external price feeds without adequate security protection.

The vulnerability does not exist in Bonzo's own smart contracts, but stems from an integration problem with the Supra oracle. This distinction is crucial. Protocols typically conduct extensive audits of internal code, but the attack surface extends to every infrastructure component they connect to. A simple flaw in the verification routine in a oracle contract is enough to drain almost all of the liquidity of the agreement. The attacker acted quickly, and when the problem was discovered, the damage was already done.

How a oracle attack occurs

Based on available information, the attacker manipulated the price oracle logic to borrow assets using inflated collateral value. Because the Supra contract failed to properly verify incoming data, malicious actors were able to submit false prices, while Bonzo's lending logic fully trusted the data. This trust is the basis of the entire loan-to-value ratio computerization. Once broken, the solvency of the agreement is lost.

Oracle attacks are not new in the DeFi space. Over the years, such attacks have affected numerous protocols on multiple chains. But the incident hit Hedera particularly hard because Bonzo has become one of the largest lending markets on the network. A 77% decline in TVL means millions of dollars in liquidity have been withdrawn, positions have been locked in, and a sharp drop in market confidence in the ecosystem's ability to withstand malicious pressures.

Hedera's DeFi vision encounters setbacks

Hedera has been quietly building its DeFi landscape, attracting projects with high throughput and fixed low fees. However, the network is still a relatively small player compared to Ethereum or BNB Chain. When top-level public chains are far ahead in developer activity, network fault tolerance space like Hedera is even more limited. A high-profile security incident could undo months of accumulated user growth.

The Bonzo incident introduced a new risk premium for institutional users and liquidity providers who had previously cautiously tested Hedera DeFi. It also forces people to think: How much does the network rely on a few oracle providers for its lending agreements? Supra's role in this incident will undoubtedly draw attention to the oracle ecosystem on permissioned and quasi-permissioned ledgers.

The oracle problem will not go away

The incident in Bonzo is not an isolated case. Oracle manipulation remains one of the most prominent attack vectors in decentralized finance because it exploits the gap between off-chain data and on-chain execution. Solutions exist-multi-source prices, time-weighted average prices, circuit breakers-but each adds complexity and cost. Smaller protocols often sacrifice security for simplicity, while smaller chains may lack sufficient infrastructure to provide robust alternatives.

The prospects for fund recovery for Bonzo users remain unclear. Although some past attacks have resulted in partial funds being returned through negotiations or white hat bounties, no feasible path has yet been identified. The agreement team needs to evaluate whether the compensation plan is feasible and how to redesign the oracle integration. For the Hedera community, the coming weeks will test whether liquidity is returning or moving out.

The broader lesson is clear. As DeFi expands into new chains, the same old vulnerabilities will follow. Unless oracle security is given the top priority from the start, more protocols will face the fate of having their liquidity pools emptied within minutes.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP