EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Cleverly exploited vulnerability to attack DeFi protocol and stole $9 million

2026-07-13 00:06:22
Bookmark

DeFi protocol was maliciously exploited and lost US$9 million

Bonzo Lend, a decentralized lending protocol on the Hedera network, suffered a serious security breach and lost approximately US$9 million. The incident stems from a flaw in the protocol's oracle mechanism that allowed attackers to manipulate the value of collateralized assets far beyond their actual levels.

How can the oracle be used?

The process of the security breach is as follows: The attacker only deposited 250 SAUCE tokens (worth only a few dollars), and then submitted tampered price data to abnormally increase the value of SAUCE by 12 orders of magnitude. The manipulation allowed the attacker to withdraw huge loans from Bonzo's liquidity pool, totaling 6.63 million USDC and 34.5 million encapsulated HBAR.

Why shouldn't Bonzo and Hedera be held accountable?

Bonzo Finance clarified that the vulnerability did not stem from its smart contract or the Hedera network itself, but rather from flaws in the way the protocol oracle system processes external pricing data, exposing it to the risk of being exploited and manipulated. Bonzo, as a DeFi platform running based on the Hedera blockchain, mainly provides mortgage asset supply and lending services. Hedera is known for improving the speed and security of decentralized applications.

Does security breach continue to threaten DeFi?

The DeFi platform is still responding to endless security threats. The number of such incidents hit a new high in the second quarter of 2026, with 83 incidents occurring in a single quarter alone, resulting in a total of $755 million in theft. Among them, cross-chain bridge vulnerability attacks accounted for US$351 million, and token price manipulation and loss of management authority were also important reasons. DeFi's total lock-in value (TVL) fell sharply by 39% in 2026, from $115 billion in January to more than $70 billion in June. A total of 121 hacking incidents occurred during the same period, causing approximately US$942 million in losses. Continuing security breaches are undermining user confidence and capital inflows.

This vulnerability is similar to previous attacks on the YieldBlox DAO lending pool on the Stellar network-the attacker also used the oracle pricing path vulnerability to steal approximately $10 million. These incidents highlight the persistent vulnerability of external data sources and price prophets in DeFi systems, and also indicate that the industry still faces continuing challenges in strengthening defenses against similar manipulations.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP