
Bonzo Finance Loses $9 Million in Oracle Exploit on Hedera
Security researchers and PeckShield flagged a suspected Hedera Network exploit moving millions of dollars to Ethereum, though the incident remains unconfirmed and under investigation.
The evolving reports place the bridged total around $3.7 million to $5.25–$5.8 million, with the attacker’s wallet holding roughly 2,360 ETH and 15.58 WBTC after converting assets on Ethereum.
Initial funding for the attack wallet is traced to 1 ETH from Tornado Cash, with the attacker allegedly using LayerZero to bridge funds across chains before swapping WBTC for ETH.
Hedera has not publicly confirmed the exploit or disclosed details, and authorities are tracking on-chain movements as part of the ongoing review.
The situation has contributed to a price dip in Hedera’s HBAR and highlights concerns about cross-chain security, echoing a prior 2023 Hedera breach that was patched quickly.
Analysts caution that attribution and total losses remain fluid as investigations continue and multiple sources provide evolving figures.
Bonzo Finance Lost Approximately $9 Million Due to an Oracle Exploit on Hedera
Bonzo Finance’s lending protocol, Bonzo Lend, on the Hedera network suffered an estimated $9.05 million loss on July 11 when an attacker exploited a flaw in a third-party price oracle. The attacker deposited minimal collateral and manipulated the SAUCE token price feed, enabling the borrowing of assets vastly exceeding the collateral value. Bonzo Lend and its points program have been paused to continue recovery efforts.
Key Points
- An attacker borrowed approximately $9 million by exploiting a third-party oracle on Bonzo Lend’s Hedera platform.
- The attacker deposited 250 SAUCE tokens worth only a few dollars, then manipulated the token’s price feed by about twelve orders of magnitude.
- The incident caused a near 40% drop in Hedera’s total value locked (TVL), representing a broader trend of rising crypto platform hacks in 2026.
Details of the Oracle Exploit
The attacker took advantage of a verification flaw in the Supra oracle contract used by Bonzo Lend. By submitting a manipulated price update, the attacker inflated the SAUCE token value drastically. Using this falsely high valuation as collateral, the attacker borrowed roughly 6.63 million USDC and 34.52 million Wrapped HBAR (WHBAR), totaling about $9.05 million at the referenced HBAR price. A second wallet borrowed an additional $1 million during the same exploitation window but later identified itself as a white-hat actor intending to return the funds. Bonzo Finance excluded these returned assets from its initial loss estimate, placing the total principal borrowed at approximately $10.06 million before recovery.
Context of Rising Crypto Security Incidents
This exploit adds to a series of significant crypto thefts in July 2026, where combined losses across three attacks exceeded $28 million. Notable incidents include a $6 million breach of the DeFi protocol Summer.fi and a $20 million governance attack on BONK DAO. Security reports indicate a roughly 50% increase in crypto security incidents during the first half of 2026, despite a decrease in total losses, highlighting growing vulnerabilities in decentralized finance (DeFi) and bridging platforms. Hedera’s total value locked declined sharply following Bonzo’s incident, reflecting investor concerns amid this surge in exploits.
Questions and answers
Q: Bonzo Finance oracle exploit
A: The Bonzo Finance oracle exploit refers to a security breach where attackers manipulated the price feed or oracle data used by the Bonzo Finance platform. This allowed them to make unauthorized trades or withdraw funds using falsified asset valuations. Oracle exploits are common in DeFi projects, highlighting the need for secure and decentralized price feeds to prevent such attacks.
Q: Hedera network crypto hack
A: The Hedera network has maintained a strong security track record, with no significant crypto hacks reported as of mid-2024. Hedera Hashgraph's consensus mechanism and permissioned model contribute to its resilience against attacks. However, like all blockchain networks, users should remain vigilant and follow best security practices to protect their assets.
Q: SAUCE token price manipulation
A: SAUCE token price manipulation involves deliberate actions by individuals or groups to artificially influence the token's market price, often through tactics like wash trading, pump-and-dump schemes, or spreading misleading information. Such manipulation distorts fair market conditions and can harm investors. It's important to verify token activity through reputable exchanges and market analytics to spot potential manipulation.
Q: 2026 DeFi security incidents
A: Predictions for 2026 DeFi security incidents suggest continued challenges as the industry grows, with potential exploits targeting smart contracts, oracles, and cross-chain bridges. Developers and platforms are expected to adopt more robust auditing, formal verification, and insurance solutions to mitigate risks. User education about security best practices will also play a key role in minimizing losses.
Q: Recover assets from crypto exploit
A: Recovering assets from a crypto exploit is challenging but sometimes possible through coordinated efforts involving blockchain analysis, law enforcement, and community support. Techniques include tracing stolen funds on-chain, freezing assets on centralized exchanges, and deploying recovery contracts or patches. However, prevention through strong security measures remains the best defense against losing assets to exploits.
Key Entities
Bonzo Finance: Bonzo Finance is a decentralized finance platform focused on offering innovative lending and borrowing solutions. It integrates with blockchain ecosystems to provide users with secure and efficient financial services.
Bonzo Lend: Bonzo Lend is a lending protocol under Bonzo Finance that enables users to borrow assets using decentralized collateral. It facilitates peer-to-peer lending on blockchain networks with competitive interest rates.
Hedera: Hedera is a public distributed ledger platform designed to support fast, secure, and scalable decentralized applications. It uses the Hashgraph consensus algorithm, offering an alternative to traditional blockchain technologies.
Supra oracle: Supra oracle provides decentralized oracle services that deliver real-world data to blockchain smart contracts. It ensures reliable and accurate data feeds, enhancing the functionality of decentralized finance applications.
Summer.fi: Summer.fi is a decentralized finance aggregator that optimizes yield farming and liquidity provision across multiple protocols. It helps users maximize returns through automated strategies and cross-chain compatibility.
External articles
- Bonzo Lend Incident Report: Oracle Provider Exploit
- Hedera-Based Bonzo Lend Loses $9 Million in Oracle Exploit
- Just In: Hedera's largest lending protocol Bonzo loses $9M ...
Articles in same category
- Netflix Q3 2025 Earnings Miss Due to Brazil Tax Dispute, Focus on Ads and Content Growth
- Bealls Inc. Partners with Flexa to Accept 99 Cryptocurrencies In-Store
- Kraken Plans AI-Powered Autonomous Trading Expansion
YouTube Video
Title: Podcast: Oracle Attack Exposes Trust Crisis | Bonzo Lend $9M Hack | Hedera DeFi in Danger
Channel: Web3 Outpost
URL: https://www.youtube.com/watch?v=02G_derbaQg
Published: 8 days ago
Crypto