Home
/
News
/
Breaking news
/

Oracle flaw enables $9 m heist on hedera's bonzo lend

Oracle Flaw Triggers $9M Heist on Hedera's Bonzo Lend | Community Divided Over Oracle Reliability

By

Fatima Ali

Jul 12, 2026, 04:03 PM

Edited By

Omar Ahmed

Updated

Jul 12, 2026, 09:50 PM

2 minutes to read

An illustration depicting a hacker manipulating data on a computer screen, with dollar signs in the background to signify stolen money from Bonzo Lend.

A significant security breach unfolded on July 11 when an attacker exploited a flaw in the oracle validation process on the Hedera network, draining nearly $9 million from Bonzo Lend, the largest lending protocol on the platform. This incident not only questions the integrity of oracle systems but also reveals dissatisfaction within the community, with some users expressing doubts about the effectiveness of the project’s council support.

Unscrambling the Flaw

The attack was executed through Wallet A, which issued a paltry 250 SAUCE tokens as collateral. The malicious player tampered with the price of the token against wHBAR by submitting an inflated value to the Supra oracle. SAUCE, at the time, was valued around 0.2 HBAR; the fraudster reported an outrageous value of 1 followed by thirty zeroes.

In a shocking maneuver, Wallet A managed to secure 6,634,528 USDC and 34,518,389 wHBAR, totaling about $9 million within eight seconds. The incident exposes a critical flaw in the oracle system, as it accepted a zeroed signature in validation.

Reactions and Community Sentiment

Responses from the community have been mixed, reflecting a growing frustration about oracle reliability. Comments highlighted several key concerns:

  1. Questioning Council Effectiveness: "They use Supra because it is cheaper. Chainlink is more expensive," one user pointed out, raising doubts about having Chainlink as a council member if it's not used effectively.

  2. Call for Redundancy: Others suggested, "Should probably have Oracle redundancy and use all 3 (Chainlink, Pyth, Supra)," pointing to a need for better defenses against such attacks.

  3. Potential Operations Collapse: Some users expressed skepticism about Bonzo's future, with comments describing the operations as "foolish" and questioning, "Does Bonzo even have $9M on lend protocol?"

"Agreed that large of a price swing should have alerted something," another comment noted, emphasizing the logical expectations of the trading mechanisms.

Analysis of the Aftermath

The aftermath saw Wallet B exploit the window to borrow around $1 million, later identifying as a white-hat hacker intending to return the funds. Bonzo Finance Labs stated, "Every price written to the Supra feed must carry a valid BLS signature," highlighting their unyielding position regarding internal coding integrity despite the breach.

Interestingly, while the Supra team has rolled out fixes to the oracle contract, critical operations at Bonzo Lend remain halted during ongoing investigations. Recovery efforts are in motion, with further announcements anticipated.

Key Points of Interest

  • πŸ” $9 million lost due to oracle manipulation

  • πŸ”’ Bonzo Lend functioning as coded despite the breach

  • πŸ› οΈ Supra oracle acknowledged the flaw and implemented corrections

  • πŸ’¬ "Should probably have Oracle redundancy" - Community suggestions grow

  • πŸ“ˆ Wallet B returned $1 million as a white-hat intervention

This incident has far-reaching implications for decentralized finance systems. Will this pressure lead to a stronger push for reliable oracle solutions, and how will community demands influence the future of lending protocols?