Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Security

Bonzo Lend Loses $9 Million in Oracle Manipulation Attack

4 reports · First detected 2026-07-11 · Last active 2026-07-12

Bonzo Lend, a decentralized lending protocol on the Hedera blockchain, suffered an oracle manipulation attack that exposed the DeFi ecosystem’s reliance on external data sources. Oracles provide real-world asset prices and are central to the operation of lending protocols. In this case, a failure in a third-party oracle verification mechanism allowed the attacker to borrow a large amount of assets with minimal collateral, raising concerns about smart-contract and cross-chain data security.

The attack occurred on July 11, 2026. Exploiting a signature vulnerability in a Supra oracle verifier, the attacker maliciously inflated the price of the SAUCE token and borrowed about $9 million in USDC and HBAR from Bonzo Lend, causing the protocol’s total value locked, or TVL, to plunge 77%. Supra subsequently deployed a fix. Officials stressed that the incident did not stem from a vulnerability in Bonzo’s smart contracts or the Hedera network itself.

All Coverage

4 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)