Edited By
Ayesha Khan

An attacker exploited a flaw in a third-party oracle, draining $9 million from Bonzo Lend, the leading lending protocol on Hedera, on July 11. With just $9 in collateral, the attacker manipulated the price input, causing chaos in the system. This incident raises serious questions about oracle reliability and security in decentralized finance.
The incident began when the attacker, identified as Wallet A, deposited 250 SAUCE tokens and submitted a manipulated price for the SAUCE/wHBAR pair to the Supra price feed. At the time, SAUCE was valued at roughly 0.2 HBAR, but the attacker inflated its apparent value by submitting a price of 1 followed by thirty zeroes. This maneuver allowed Wallet A to borrow an astounding $9 million, including 6,634,528 USDC and 34,518,389 wHBAR, within seconds.
โThe verifier trusted a correct answer to the wrong question,โ Bonzo Finance Labs stated in their report, pinpointing the flaw in the oracleโs verification process. The oracle accepted a zeroed signature, leading to improper validations and a significant loss.
Reactions from the community have been largely negative, with many expressing disappointment at the vulnerability.
โThis is a black mark on the ecosystem,โ lamented one commentator.
Others criticized the choice of Supra, questioning its reliability compared to alternatives like Chainlink. โThey use Supra because it is cheaper,โ said a user.
Some participants suggested oracle redundancy could have prevented the attack. โWe should probably have Oracle redundancy and use all 3,โ referring to potential backup services.
๐ถ Wallet A drained $9 million using a flawed oracle update.
๐น Bonzo Lendโs contracts were operational as intended; fault lies with the oracle system.
๐ธ $1 million was borrowed by another wallet (Wallet B) before legitimate prices were restored, but those funds may be returned.
๐น Bonzo Lend is currently paused while recovery efforts are coordinated.
Following the incident, Supra has acknowledged the issue and implemented a fix. While Bonzo Lend and Bonzo Points remain paused, Bonzo Vaults and single-sided $BONZO staking are unaffected. The wider community will be keenly watching how recovery efforts unfold amid significant criticism regarding the security measures in place.
As conversations around blockchain security evolve, this incident underscores the necessity of robust oracle systems, particularly in decentralized finance frameworks. How will platforms ensure such vulnerabilities are addressed in the future?
In the aftermath of this significant breach, there's a strong chance that Bonzo Lend will implement critical changes to bolster its security measures. Experts estimate around a 70% probability that they will adopt oracle redundancy across multiple services to mitigate future vulnerabilities. Additionally, discussions around upgrading to more established oracle solutions, like Chainlink, could gain momentum. As the community pushes for improvements, we might see updates aimed at restoring trust and enhancing transparency within decentralized finance platforms. Monitoring the outcome of these proposed changes will be crucial as they determine the protocolโs resilience against further attacks.
The scenario mirrors the 2016 DAO hack, which sent shockwaves through the Ethereum community. Just like Bonzo Lend, that platform suffered a significant loss due to a flaw in smart contract code, leading to widespread panic and a hard fork in the Ethereum blockchain. This event not only redefined community governance but also highlighted the need for rigorous code audits in blockchain systems. Just as that breach prompted Ethereumโs evolution, Bonzo Lendโs current crisis may result in a more robust lending protocol landscape. The resilience of crypto innovations often emerges from adversity, hinting that this incident could ultimately lead to stronger foundations for future protocols.