{"id":5260,"date":"2026-07-12T09:32:43","date_gmt":"2026-07-12T08:32:43","guid":{"rendered":"https:\/\/kriptoblog.hu\/?p=5260"},"modified":"2026-07-25T02:57:43","modified_gmt":"2026-07-25T01:57:43","slug":"bonzo-lend-9-05-millio-dollaros-veszteseget-okozott-egy-oracle-hiba-3819","status":"publish","type":"post","link":"https:\/\/kriptoblog.hu\/en\/bonzo-lend-9-05-millio-dollaros-veszteseget-okozott-egy-oracle-hiba-3819\/","title":{"rendered":"Bonzo Lend: Oracle Bug Causes $9.05M Loss"},"content":{"rendered":"<p>\nBy early Saturday, one of the most closely followed players in the Hedera DeFi segment, Bonzo Lend, suffered significant losses\u2014not due to a flaw in its own code, but because of an external price oracle it relied upon. The story is a familiar one in decentralized lending: the protocol's contract logic functioned correctly, but the input data it relied on was false. The consequences are particularly sharp here because the flaw was exposed in another provider's, Supra's, verifier contract, draining the lending pool's liquidity within minutes.\n<\/p>\n<h2>The Attack Sequence<\/h2>\n<p>\nAccording to the official incident report from Bonzo Finance Labs, the attack began on July 11, 2026, at approximately 00:51 UTC. The attacker deposited only 250 SAUCE tokens as collateral\u2014valued at just a few dollars according to the report. The trick lay not in the amount of collateral, but in its price: a manipulated price update via a third-party Supra oracle contract artificially inflated the value of SAUCE denominated in HBAR.\n<\/p>\n<p>\nAccording to a report by CoinDesk, with this inflated collateral, the attacker borrowed 6.63 million USDC and 34.52 million wrapped HBAR from the Bonzo Lend lending pool, totaling approximately $9.05 million. This borrowing represents a textbook example of the classic oracle manipulation scheme: the loan assets were requested at a realistic market price, while the collateral side of the system accepted a false price.\n<\/p>\n<h2>A Zero Signature That Should Not Have Been Accepted<\/h2>\n<p>\nAccording to a technical description by crypto.news, the source of the flaw lay in the Supra signature verification process. The price update did not carry a genuine signature from the Supra oracle committee; instead, a zero, null signature arrived. The verifier contract\u2014which was precisely supposed to discard invalid messages\u2014analyzed these zero values as identity-value points in the pairing mathematics, thereby accepting the false price update as valid.\n<\/p>\n<p>\nIn a common analogy: imagine a doorman who must check an entry card before letting someone in. If someone hands over an empty envelope, the doorman would normally turn them away. Here, however, the system interpreted the empty envelope as if it had arrived with an official, \"empty\" seal\u2014mathematically, this was a valid input, but it represented no real signature. The pairing precompile answered the narrow mathematical question correctly; the flaw was in the verifier, which did not explicitly reject zero values and identity points.\n<\/p>\n<p>\nAccording to the crypto.news report, just eight seconds after the false price reached the Hedera mainnet, the attacker had already executed the borrowing. This precise timing is currently only documented by crypto.news; other sources have not confirmed it\u2014so it should be treated with caution. However, the essence remains unchanged: it was a pre-prepared operation on a second-by-second scale.\n<\/p>\n<h2>Response Steps and a Surprising Turn<\/h2>\n<p>\nAccording to the report from Bonzo Finance Labs, the team paused Bonzo Lend at 01:41 UTC, and the lending pool has remained locked since. This selective pause is a significant signal: the team knew precisely that the problem was limited to the price input arriving at Lend and did not want to penalize users of other products with a global shutdown.\n<\/p>\n<p>\nA second wallet is mentioned in the CoinDesk report, which borrowed an additional approximately $1 million worth of assets from the protocol during the abnormal price period. The report states that this address later identified itself as a white-hat responder and indicated an intention to return the borrowed amount. Such a turn is not unprecedented on the DeFi side, but it is never guaranteed\u2014one should only count on a refund when the transaction is actually reversed.\n<\/p>\n<h2>Market Shock on Hedera<\/h2>\n<p>\nAccording to CoinDesk data, the total DeFi TVL on the Hedera network fell by nearly 40 percent within 24 hours, while Bonzo's own TVL plummeted by 77 percent. This level of capital flight\u2014before a concrete reimbursement plan or coverage framework was made public\u2014clearly shows how sensitive users are to oracle-origin incidents. A smart contract flaw is often categorized by the market as bad luck; an oracle flaw, however, is often experienced as a structural trust issue because the entire DeFi ecosystem relies on it.\n<\/p>\n<p>\nAccording to reports from crypto.news, the Supra oracle deployed a fix on the affected verifier contract on the Hedera mainnet. This is important, but it does not refute the longer-term question of how much a lending protocol can rely on a single external price source for collateral decisions.\n<\/p>\n<h2>What We Can Learn From This\u2014and What We Cannot<\/h2>\n<p>\nIn its own report, Bonzo Finance Labs explicitly stated that the loss did not stem from Bonzo Lend's contracts or design decisions, but from the upstream third-party oracle. This is a technically defensible claim, and the available on-chain evidence supports it. However, a lending protocol's ultimate responsibility remains to vet the inputs it uses: which oracle, which signature model, which redundancy, and which upper price-change limit are used to accept an update. The market is increasingly less willing to overlook this distinction based on past accidents. In the Bonzo case, what was particularly missing from the multi-layered defense was that the external oracle's accepted, multi-order-of-magnitude price spike was not stopped by the lending protocol's own price-change limit or a second data source. Therefore, the upstream fix is necessary but does not replace protocol-side protection.\n<\/p>\n<p>\nA few calm conclusions are available for the reader. First: on the side of low-liquidity, low-value collateral assets, oracle manipulation is not theoretical but a recurring risk\u2014it is worth checking which tokens a lending protocol accepts and under what limits. Second: oracle diversification, as well as caps on the speed and magnitude of price changes (circuit breakers), are not a luxury but basic protection. Third: extraordinary returns almost always hide some form of systemic risk\u2014the feeling that \"this time will be different,\" which the market likes to stir up, is also present here, and it is worth slowing down before acting.\n<\/p>\n<p>\nNothing in this article constitutes financial advice. Anyone affected by the Bonzo pool would do well to follow updates from the official incident report and decide on their next steps in light of their own risk tolerance.\n<\/p>\n<p>\nThe story remains open: Bonzo Finance Labs indicated that separate statements regarding compensation and next steps will be issued. Until these arrive, the most important lesson is the mechanism itself: a single accepted empty signature, a single mishandled special case\u2014and the system amplified the flaw into a lending-pool-sized loss within minutes. In the coming year of DeFi, we will once again ask the old question: not the smart contract, but the data it relies on, how reliable is it?\n<\/p>\n<h2>Sources<\/h2>\n<ul>\n<li>Bonzo Finance Labs \u2014 Bonzo Lend Incident Report: Oracle Provider Exploit \u2014 <a href=\"https:\/\/bonzo.finance\/blog\/bonzo-lend-incident-report-oracle-provider-exploit\" target=\"_blank\" rel=\"noopener\">bonzo.finance<\/a> (2026-07-11)<\/li>\n<li>CoinDesk \u2014 Bonzo Lend&#8217;s total value locked plunges 77% as $9 million oracle exploit rattles Hedera \u2014 <a href=\"https:\/\/www.coindesk.com\/web3\/2026\/07\/11\/lending-protocol-bonzo-loses-77-of-value-locked-as-usd9-million-oracle-exploit-rattles-hedera\" target=\"_blank\" rel=\"noopener\">coindesk.com<\/a> (2026-07-11)<\/li>\n<li>crypto.news \u2014 Bonzo Lend loses $9M after oracle flaw inflates SAUCE price \u2014 <a href=\"https:\/\/crypto.news\/bonzo-lend-loses-9m-after-oracle-flaw-inflates-sauce-price\" target=\"_blank\" rel=\"noopener\">crypto.news<\/a> (2026-07-11)<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Bonzo Lend protocol lost $9.05M in Hedera after a Supra oracle verifier accepted a manipulated SAUCE price update.<\/p>","protected":false},"author":1,"featured_media":5258,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[970,137,974,971,973,972],"class_list":["post-5260","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hirek","tag-bonzo-lend","tag-defi","tag-exploit","tag-hedera","tag-oracle","tag-supra"],"_links":{"self":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5260","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/comments?post=5260"}],"version-history":[{"count":1,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5260\/revisions"}],"predecessor-version":[{"id":5262,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5260\/revisions\/5262"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/media\/5258"}],"wp:attachment":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/media?parent=5260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/categories?post=5260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/tags?post=5260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}