Bonzo Lend Suffers $9 Million Loss Due to Exploited Supra Oracle Vulnerability

Cross-chain and price-oracle breakdown: cross-chain bridge exploits accounted for about $351 million, while compromised administrator attacks and fake token price manipulation represented approximately 37% of quarterly losses in the period.
Broader DeFi market stress context: DeFi total value locked fell about 39% to just over $70 billion by June 2026, as market-wide incidents persisted andCryptoRank tracked a large number of hacks and losses during the period.
Stellar ecosystem precedent: a February collateral-pricing exploit on Stellar drained roughly $10 million from YieldBlox DAO’s lending pool, highlighting cross-chain risk to DeFi lending platforms.
Specificity of the oracle flaw: the incident is attributed to Supra’s on-chain oracle verifier accepting a manipulated SAUCE price data point carrying a zeroed signature; Supra acknowledged the issue and fixed it, with Bonzo Lend stressing the problem did not lie in its own contracts or Hedera’s network.
Bonzo Lend, the largest lending protocol on the Hedera blockchain, lost roughly $9 million after an attacker manipulated a token's price to borrow far more than their collateral was worth, according to CoinDesk and KuCoin. The hacker started with just 250 SAUCE tokens as collateral, then exploited a flaw in a third-party oracle to inflate SAUCE's price by about 12 orders of magnitude — effectively turning a tiny deposit into a blank check.
The attacker walked away with 6.63 million USDC and 34.5 million wrapped HBAR. Crypto Times reported that roughly $5.25 million of the stolen funds were later bridged to Ethereum, making recovery harder. Bonzo Lend's total value locked dropped 77% in the aftermath.
The attack targeted Supra's on-chain oracle verifier — a tool that feeds external price data into DeFi protocols. According to CoinDesk, the verifier accepted a manipulated SAUCE price data point that carried a zeroed signature, meaning the price had no valid cryptographic proof backing it. The system accepted it anyway.
That single flaw let the attacker borrow against a wildly inflated collateral value. Bonzo Lend was clear that the bug was not in its own contracts or in Hedera's network. Supra acknowledged the problem and deployed a fix after the exploit, according to KuCoin.
Bonzo Lend publicly stressed that its own code was not at fault. The team said the exploit came entirely from outside — specifically from Supra's oracle verifier contract. Bloomingbit noted that this kind of oracle price manipulation attack is a known risk in DeFi, where protocols rely on external price feeds they do not fully control.
Oracles are the bridges between real-world prices and on-chain smart contracts. When they fail — or are tricked — the results can be catastrophic. Supra's fix came after the damage was done. The episode raises serious questions about how much protocols should trust third-party price feeds without extra safeguards.
The Bonzo Lend attack did not happen in isolation. The second quarter of 2026 saw 83 separate DeFi exploits totaling about $755 million in losses, according to KuCoin. Cross-chain bridge exploits alone accounted for roughly $351 million of that total. Compromised administrator keys and fake token price manipulation drove about 37% of quarterly losses.
DeFi's total value locked fell about 39% to just over $70 billion by June 2026. A similar collateral-pricing exploit hit YieldBlox DAO on the Stellar network in February, draining roughly $10 million from its lending pool. That attack, like the Bonzo Lend incident, showed how lending protocols are especially vulnerable when collateral prices can be manipulated.
The hack rattled confidence in Hedera's DeFi ecosystem. Bonzo Lend held the top spot among Hedera lending protocols before the attack. A 77% drop in total value locked shows how quickly users pulled funds once news broke, according to CoinDesk. Restoring trust will depend on what safeguards Bonzo adds around its oracle dependencies.
Crypto Times reported the $5.25 million bridged to Ethereum makes a full recovery unlikely. Supra's patch fixes the immediate flaw, but the incident shows a wider problem: DeFi protocols often inherit the risks of every tool they plug into. One weak link in a third-party contract can undo an otherwise sound protocol.
Publishers
17
Articles
12
Reach
29