Bonzo Hack
Reported loss
$9.1M
Oracle Issue
What happened
On July 11, 2026, Bonzo Lend on Hedera was affected after an upstream third-party oracle verifier accepted a manipulated SAUCE price update. The malicious wallet used 250 SAUCE as collateral to borrow principal that Bonzo reports at approximately $9.05 million; Bonzo Lend was paused.
How it happened
- The malicious wallet deposited 250 SAUCE into Bonzo Lend as collateral.
- It submitted a manipulated SAUCE/wHBAR price update to the third-party oracle's pull contract; the verifier accepted a proof with no valid signature and stored the price.
- The stored value overstated SAUCE by roughly twelve orders of magnitude, letting the wallet borrow USDC and WHBAR far beyond the collateral's real value.
- Bonzo paused the lending pool after the abnormal price was restored; it treats a separate wallet's borrowing as a potential recovery matter rather than headline loss.
Protocol details
Classification
Borrowing and Lending / Oracle Manipulation
Protocol Type
Exploit/Oracle Issue
Implementation language
Solidity
Protocol links
Website
@bonzo_finance
Market Context at Time of Hack
Token Price at Hack
$0.0125
Protocol Links
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.