DeFi protocol was maliciously exploited and lost US$9 million
Bonzo Lend, a decentralized lending protocol on the Hedera network, suffered a serious security breach and lost approximately US$9 million. The incident stems from a flaw in the protocol's oracle mechanism that allowed attackers to manipulate the value of collateralized assets far beyond their actual levels.
How can the oracle be used?
The process of the security breach is as follows: The attacker only deposited 250 SAUCE tokens (worth only a few dollars), and then submitted tampered price data to abnormally increase the value of SAUCE by 12 orders of magnitude. The manipulation allowed the attacker to withdraw huge loans from Bonzo's liquidity pool, totaling 6.63 million USDC and 34.5 million encapsulated HBAR.
Why shouldn't Bonzo and Hedera be held accountable?
Bonzo Finance clarified that the vulnerability did not stem from its smart contract or the Hedera network itself, but rather from flaws in the way the protocol oracle system processes external pricing data, exposing it to the risk of being exploited and manipulated. Bonzo, as a DeFi platform running based on the Hedera blockchain, mainly provides mortgage asset supply and lending services. Hedera is known for improving the speed and security of decentralized applications.
Does security breach continue to threaten DeFi?
The DeFi platform is still responding to endless security threats. The number of such incidents hit a new high in the second quarter of 2026, with 83 incidents occurring in a single quarter alone, resulting in a total of $755 million in theft. Among them, cross-chain bridge vulnerability attacks accounted for US$351 million, and token price manipulation and loss of management authority were also important reasons. DeFi's total lock-in value (TVL) fell sharply by 39% in 2026, from $115 billion in January to more than $70 billion in June. A total of 121 hacking incidents occurred during the same period, causing approximately US$942 million in losses. Continuing security breaches are undermining user confidence and capital inflows.
This vulnerability is similar to previous attacks on the YieldBlox DAO lending pool on the Stellar network-the attacker also used the oracle pricing path vulnerability to steal approximately $10 million. These incidents highlight the persistent vulnerability of external data sources and price prophets in DeFi systems, and also indicate that the industry still faces continuing challenges in strengthening defenses against similar manipulations.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
HBAR