Bonzo Lend Loses 77% of Value Locked in $9M Oracle Exploit on Hedera
Decentralized lending protocol Bonzo Lend lost $9.05 million on Hedera after an attacker manipulated a Supra price oracle. The exploit cut Bonzo's total value locked by 77% and dragged Hedera's DeFi deposits down nearly 40% in a day.

Attacker drains $9 million from Bonzo Lend on Hedera
An attacker stole about $9.05 million from Bonzo Lend, a decentralized lending protocol on the Hedera network, in an oracle exploit that began around 00:51 UTC on 11 July 2026. Decentralized finance (DeFi) lets users borrow and lend crypto without a bank or broker. The theft struck Hedera's largest lending protocol and rattled activity across the wider network.
Manipulated oracle let attacker borrow against a tiny deposit
The attacker exploited a verification flaw in a third-party Supra oracle contract, which the protocol relied on for token prices. After depositing 250 SAUCE tokens worth only a few dollars, the attacker submitted a manipulated price update that inflated the token's value far beyond its market rate. That false price let the wallet borrow 6.63 million USD Coin (USDC) and 34.52 million wrapped HBAR (WHBAR) against almost no real collateral. A second wallet borrowed a further $1 million during the incident.
Bonzo's value locked fell 77% after the exploit
Bonzo's total value locked (TVL) — the amount of crypto deposited in the protocol — fell 77% after the incident. Hedera's network-wide TVL dropped nearly 40% in 24 hours to $25.7 million, according to DeFi tracker DefiLlama. Blockchain security firm PeckShield reported that about $5.25 million was bridged from Hedera to Ethereum after the attack.
Bonzo paused lending as Supra patched the flaw
Bonzo paused Bonzo Lend and Bonzo Points after the exploit, while its vaults, bridge, and BONZO staking kept running. The team said the fault lay in Supra's oracle verification, not its own smart contracts, which used the incorrect on-chain price as designed. Supra acknowledged the vulnerability and deployed a fix for the affected verifier. One wallet involved identified itself as a white-hat responder and said it intended to return the funds.
Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.
All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.
Coinpaprika is not liable for any losses resulting from the use of this information.