Particle.news

Bonzo Loses $9M After Oracle Verifier Flaw on Hedera

A flaw in Supra’s on-chain oracle verifier let an attacker inflate SAUCE prices, thereby enabling a roughly $9 million borrowing that raises broad doubts about oracle reliance on Hedera.

Overview

  • Reporting on July 11, 2026 says an attacker exploited a verification bug in Supra’s on-chain oracle to inflate the HBAR-denominated price of SAUCE and borrow about $9.05 million from Bonzo’s lending pools.
  • The attacker deposited low-value SAUCE, submitted a manipulated price update that raised its on-chain value, and withdrew roughly 6.63 million USDC plus 34.52 million wrapped HBAR while the false price was active.
  • A second wallet borrowed about $1 million during the incident and one wallet later messaged Bonzo claiming to be a white-hat and offering to return funds; Bonzo excluded any returned assets from its headline loss figure.
  • Bonzo adapted Aave v2 for Hedera and chose Supra for price feeds in March 2024 because Chainlink was not available, and the protocol previously paused markets in February 2025 after suspicious HBAR price activity.
  • The exploit cut Bonzo’s total value locked by roughly 77% and pushed Hedera’s TVL down about 40%, highlighting that oracle-layer failures can bypass audits and create wider systemic risk for Hedera’s DeFi users.