Bonzo Lend loses $9M in oracle exploit on Hedera
Hedera-based lending protocol Bonzo Lend lost about $9 million after an attacker manipulated the price of the SAUCE token used as collateral, allowing the account to borrow assets far beyond the value deposited. In a preliminary incident report published Saturday, Bonzo said the attacker deposited 250 SAUCE, worth only a few dollars, before submitting a price update that inflated the tokens value by roughly 12 orders of magnitude. The wallet then borrowed 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool. The case illustrates how oracle failures can turn low-value collateral into a tool for draining large amounts of liquidity from lending protocols, even when the application and underlying network continue operating as designed. Bonzo attributed the incident to a flaw in Supras onchain oracle verifier, which accepted a manipulated SAUCE price carrying a zeroed signature, that is, a digital signature that has no content or is empty, effectively deleting any existing signature. The protocol said Supra acknowledged the issue and deployed a fix, while stressing that the incident was not a vulnerability in Bonzo Lend‘s contracts or Hedera’s core network. Estimated economic impact of the incident. Source: Bonzo Finance DeFi hacks continue to pressure the sector The incident adds to a growing number