On July 11, 2026, Bonzo Lend, a decentralized lending protocol on the Hedera blockchain, fell victim to an oracle manipulation attack that resulted in losses of approximately $9 million. The attacker started with just 250 SAUCE tokens — worth only a few dollars at market price. Subsequently, the attacker submitted a manipulated price update that inflated SAUCE’s value by about 12 orders of magnitude. Leveraging this artificially inflated collateral, the attacker borrowed 6.63 million USDC and 34.5 million wrapped HBAR from Bonzo’s liquidity pool.
Attack Method: 250 SAUCE as Collateral, Oracle Value Inflated by 12 Orders of Magnitude
Preliminary investigations revealed that the exploit centered on Bonzo Lend’s reliance on on-chain oracle pricing data. The attacker first deposited a minuscule amount of SAUCE, then exploited a flaw in Supra’s on-chain oracle verifier by submitting a manipulated price update with a zeroed signature, instantly multiplying SAUCE’s value. This turned negligible collateral into a tool for siphoning millions from the liquidity pool. Bonzo Finance acknowledged that the vulnerability stemmed from Supra’s verifier, which failed to adequately filter bogus price updates.
Root Cause: Supra Oracle Verifier Flaw, Not Contract or Network Issues
Bonzo Finance emphasized that the attack did not originate from flaws in its own smart contracts or the underlying Hedera network. The problem lay in how the protocol’s oracle system verified external price data, leaving it vulnerable to manipulation. Supra, the company providing the affected oracle, acknowledged the issue and deployed a fix. Bonzo Lend is a DeFi lending protocol on Hedera that allows users to deposit assets as collateral and borrow others. Hedera is a public distributed ledger platform known for fast, secure decentralized applications.
DeFi Security Landscape in Q2 2026: 83 Exploits, $755M Lost
This attack adds to a growing tally of DeFi exploits in 2026. According to research firm CryptoRank, the second quarter saw 83 incidents with total losses of about $755 million. Cross-chain bridge exploits accounted for $351 million, while incidents involving compromised administrators and token price manipulation represented 37% of quarterly losses. Overall, DeFi’s total value locked (TVL) fell by 39% in 2026, dropping from roughly $115 billion in January to over $70 billion by June. The firm reported 121 hacks in the first half, with estimated losses of $942 million, indicating that recurring security incidents continued to erode user trust and drive capital outflows.
Similar Case: YieldBlox DAO Lost $10M via USTRY Price Path Manipulation
Earlier this year, the YieldBlox DAO lending pool on the Stellar network suffered a comparable attack. Attackers manipulated the price path used to value USTRY collateral, draining roughly $10 million after borrowing assets far exceeding the token’s actual value. These incidents highlight persistent challenges with oracles and external data feeds in decentralized finance—price oracles remain prime targets for sophisticated exploits despite advances in smart contract security and blockchain infrastructure.

