Bonzo Finance, a lending protocol built on Hedera, lost about $9 million in an oracle attack, according to Odaily. In its preliminary incident report, the protocol said the attacker deposited just 250 SAUCE tokens, then submitted a price update that artificially inflated SAUCE by roughly 12 orders of magnitude. Using the overstated collateral value, the attacker borrowed assets far beyond their real worth from the lending pool.
Bonzo Finance said the address went on to borrow 6.63 million USDC and 34.5 million wrapped HBAR. The protocol added that the incident was not caused by a flaw in Bonzo Finance’s smart contracts or in the Hedera base network itself. Instead, it traced the issue to a vulnerability in the on-chain oracle validator operated by oracle provider Supra.
According to the report, Supra’s validator incorrectly accepted SAUCE price data with a zeroed signature. Supra has since confirmed the issue and completed a fix. The case highlights how oracle failures can expose lending markets even when the core protocol logic is not identified as the direct source of the exploit.
Bonzo Finance, a Hedera-based lending protocol, lost about $9 million in an oracle attack, according to Odaily.
In a preliminary incident report, Bonzo Finance said the attacker deposited only 250 SAUCE tokens and then submitted a price update that artificially pushed the token’s price higher by about 12 orders of magnitude. With that inflated collateral, the attacker borrowed assets worth far more than their actual value from the protocol.
The report said the address borrowed 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool.
Issue traced to Supra oracle validator
Bonzo Finance said the exploit did not stem from a flaw in its smart contracts or from the Hedera base network itself. It attributed the incident to a vulnerability in the on-chain oracle validator run by oracle provider Supra.
According to the protocol, the validator incorrectly accepted SAUCE price data carrying a zeroed signature. Supra has confirmed the issue and said the problem has been fixed.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.