Bondly Hack

Reported loss $6.8M
Ethereum
Private Key Compromised (Unknown Method)

What happened

On July 15, 2021, an attacker gained control of Bondly's Staking Rewards wallet, transferred 373,088,023 BONDLY, and supplied 200,460,000 BONDLY to MANTRA DAO ZENTEREST to borrow other assets. MANTRA said ZENTEREST's own smart contracts were not compromised and that supplied-user funds would be restored.

How it happened

  1. The attacker obtained control of Bondly's Staking Rewards wallet.
  2. They transferred 373,088,023 BONDLY to their wallet.
  3. They supplied 200,460,000 BONDLY to ZENTEREST and minted zenBONDLY.
  4. They used that position to borrow assets from ZENTEREST before the market was paused.

Protocol details

Classification Infrastructure / Other / Social Engineering
Protocol Type Exploit/Access control
Affected asset / contract BONDLY
Implementation language Solidity
Protocol links Website @BondlyFinance

Funds Recovery

100.0%

Recovered

$6.8M

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.