Bondly Hack
What happened
On July 15, 2021, an attacker gained control of Bondly's Staking Rewards wallet, transferred 373,088,023 BONDLY, and supplied 200,460,000 BONDLY to MANTRA DAO ZENTEREST to borrow other assets. MANTRA said ZENTEREST's own smart contracts were not compromised and that supplied-user funds would be restored.
How it happened
- The attacker obtained control of Bondly's Staking Rewards wallet.
- They transferred 373,088,023 BONDLY to their wallet.
- They supplied 200,460,000 BONDLY to ZENTEREST and minted zenBONDLY.
- They used that position to borrow assets from ZENTEREST before the market was paused.
Protocol details
Funds Recovery
Recovered
$6.8M
Net Loss
$0
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.