Bonzo Exploit Drains $9M From Hedera’s Largest Lending Protocol, Underscoring Cross‑Chain Oracle Risk

Lending markets on alternative layer‑1 networks rarely command the attention of their Ethereum‑mainnet peers—until a multimillion‑dollar drain forces the issue. That moment came for Hedera’s Bonzo on July 11, when the protocol disclosed it had lost roughly $9.05 million in an oracle manipulation attack. The incident, first documented in the original report, immediately spotlighted the fragility of price feeds on chains where liquidity is thinner and user safeguards often rely on a single oracle provider. Bonzo functioned as Hedera’s largest lending protocol by total value locked, a critical piece of an ecosystem still building its DeFi footprint. The protocol paused all activity after the exploit. Bonzo Labs and the Bonzo Finance Foundation are now coordinating what they describe as recovery and remediation efforts, though no timeline or roadmap for user compensation has been offered publicly. What Went Wrong: Supra’s Oracle and a Signature Verification Loophole The exploit did not originate in Bonzo’s own smart‑contract logic. According to the team, a flaw in Supra’s signature verification mechanism allowed an attacker to feed manipulated SAUCE prices into the lending market. With a distorted price feed for SAUCE—the native token of the SaucerSwap decentralized exchange on Hedera—the exploiter was able to borrow assets far in excess of the collateral they had posted. The mechanics follow a pattern DeFi has seen before: inflate the collateral’s value artificially, then drain borrowable liquidity before the oracle corrects. Supra’s role is central here. As a cross‑chain oracle network, it supplies pricing data to protocols across multiple ecosystems. When a verification flaw sits at the oracle level, the blast radius can extend beyond a single application. Bonzo paused quickly, but the speed of the drain suggests an attacker who understood precisely where the weak link sat. Hedera’s DeFi Moment and the Thin‑Margin Reality For Hedera, whose enterprise‑governed consensus model has attracted institutional interest, the Bonzo incident is a formative stress test. The chain’s DeFi sector is still immature relative to Ethereum or Solana; lending protocols on Hedera typically hold lower total value locked and face thinner order‑book depth. That environment can make oracle manipulation less costly for an attacker because markets are easier to move temporarily. The exploit also underscores a persistent dilemma for chains that rely on third‑party oracles rather than native price‑discovery mechanisms. When a single oracle provides the pricing for a suite of applications, an error at the supplier can cascade. Bonzo’s case joins a list of prior oracle attacks—from Cream Finance to Mango Markets—where manipulated prices were the entry point, not the exit. The difference here is the chain: a network that has marketed itself as enterprise‑ready is now dealing with a DeFi blow that retail and institutional users alike will scrutinize.
عنوان اصلی (انگلیسی): Bonzo Exploit Drains $9M From Hedera’s Largest Lending Protocol, Underscoring Cross‑Chain Oracle Risk
مشاهدهی خبر کامل در منبع ↗ بازگشت به SaucerSwapاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.