- Bonzo Lend was exploited for approximately $9 million.
- The attacker manipulated a third-party oracle price feed.
- Lending markets have been paused while investigations continue.
- Supra has patched the vulnerability that enabled the attack.
Hedera-based lending protocol Bonzo Lend has suffered a roughly $9 million exploit after attackers manipulated a price update from third-party oracle provider Supra.
The attacker deposited a small amount of SAUCE tokens as collateral before exploiting a flaw that allowed an invalid price update to be accepted. This temporarily inflated the token's value, allowing millions of dollars in USDC and wrapped HBAR to be borrowed against nearly worthless collateral.
Following the attack, Bonzo paused its lending markets while Supra deployed a fix for the affected oracle verifier. A second wallet that borrowed another $1 million identified itself as a white-hat hacker and said it intends to return the funds.
The exploit highlights the growing importance of securing oracle infrastructure, as vulnerabilities outside a protocol's own smart contracts continue to be a major source of DeFi hacks.