Bonzo Lend Loses $9 Million in Oracle Manipulation Attack
Bonzo Lend, a decentralized lending protocol on the Hedera blockchain, suffered an oracle manipulation attack that exposed the DeFi ecosystem’s reliance on external data sources. Oracles provide real-world asset prices and are central to the operation of lending protocols. In this case, a failure in a third-party oracle verification mechanism allowed the attacker to borrow a large amount of assets with minimal collateral, raising concerns about smart-contract and cross-chain data security.
The attack occurred on July 11, 2026. Exploiting a signature vulnerability in a Supra oracle verifier, the attacker maliciously inflated the price of the SAUCE token and borrowed about $9 million in USDC and HBAR from Bonzo Lend, causing the protocol’s total value locked, or TVL, to plunge 77%. Supra subsequently deployed a fix. Officials stressed that the incident did not stem from a vulnerability in Bonzo’s smart contracts or the Hedera network itself.
All Coverage
4 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →