Wire
07:15ZGAZAENGLISHearing an explosion in Gaza City💣the IDF is bombing citizens' homes in northern Gaza Strip💣Bombing of resi…07:13ZDAILYNATIONairobi Senator Edwin Watenya Sifuna admits he has always dreamed of leading Kenya07:11ZJAHANTASNIHezbollah parliament member says Israel's apparent retreat is deceptive show07:10ZTASNIMPLUSFormer Iranian diplomat: White House confused by Iran07:09ZCLASHREPORAndy Burnham says he would challenge Trump to defend British interests07:08ZCLASHREPORBrazil blocks visas for two senior U.S. State Department officials, preventing planned visit07:08ZTASNIMNEWSMazandaran offices in Iran to close Sunday07:07ZOSINTLIVERussian forces hit Epicentr hypermarket in Kryvyi Rih, massive fire reported
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusCrypto

A $9 million oracle bug just hollowed out Bonzo Lend

An attacker walked away with roughly $9.05 million from Bonzo Lend by inflating the price of a collateral token through a third-party Supra oracle, exposing the structural fragility of DeFi's price-feed layer.

Hedera, the distributed-ledger network where Bonzo Lend operated, has marketed itself as an enterprise-grade alternative to Ethereum.
Hedera, the distributed-ledger network where Bonzo Lend operated, has marketed itself as an enterprise-grade alternative to Ethereum. CoinDesk / CT Media

An attacker drained roughly $9.05 million from Bonzo Lend on 11 July 2026, exploiting a verification flaw in a third-party Supra oracle contract on the Hedera network. Within hours of the exploit, the total value locked on the lending protocol collapsed by 77 percent, according to CoinDesk reporting. The incident lands as the latest in a string of oracle-manipulation episodes that have become the single most expensive category of attack in decentralised finance.

Bonzo Lend's collapse is more than another nine-figure hack. It is a stress test of an architecture the rest of DeFi has been quietly copying: a lending market that delegates its price truth to an outside feed, and an outside feed that delegates its own integrity to an external verifier. When any link in that chain bends, the entire structure falls. The chain bent on Friday, and the structure fell.

What actually happened on Hedera

According to CoinDesk and Cointelegraph, both citing on-chain forensics, the attacker inflated the value of SAUCE, a collateral token used inside Bonzo Lend, and then borrowed against that inflated collateral to walk away with approximately $9 million in liquidity. The mechanism was not a bug in Bonzo's own contracts in the narrow sense; the loan book did what it was told. The vulnerability lived one layer up, inside Supra's on-chain oracle verifier, which is supposed to attest that prices pushed on-chain match prices read from legitimate sources.

That single point of failure turned a routine collateral check into a withdrawal slip. Once SAUCE's reference price on Supra's feed was warped upward, the protocol's loan-to-value math treated the attacker as someone flush with high-value collateral, and extended credit accordingly. CoinDesk's reporting puts the lost sum at about $9.05 million; Cointelegraph's wires converge on a $9 million figure. The total value locked on the protocol, which had been one of the more active markets on Hedera's DeFi segment, fell by 77 percent in the immediate aftermath.

The structural lesson is not that Bonzo's engineers are incompetent. It is that DeFi lending markets, as a class, are structurally exposed to whatever price oracle they choose to trust. Bonzo trusted Supra. Supra's verifier was the load-bearing wall. The wall cracked.

The oracle layer nobody audits

Oracles are the part of decentralised finance that most users never read about and most protocols treat as plumbing. They are also the part that gets exploited the most. Industry tallies over the last three years have consistently placed oracle manipulation among the top two or three vectors for large-dollar DeFi losses, alongside private-key compromises and flawed cross-chain bridges.

The economics explain why. Lending protocols are, at heart, margin engines. They need to know, in real time, what every piece of collateral is worth, and they need that number to be the same number every other market can see. Building that oracle in-house is expensive and difficult; buying it from a third party is cheap and fast. The market has rewarded cheap and fast. The cost of that reward is paid in episodes like Friday's.

Supra, the feed Bonzo used, sells itself on multi-source aggregation and on-chain verification, the latter being a relatively newer design that tries to replace a single trusted reporter with cryptographic attestation. That design has theoretical appeal. It also creates a new attack surface: the verifier contract itself. When the verifier is the bottleneck, an attacker who can spoof what the verifier sees controls the price.

The Hedera question

The incident also puts a fresh mark on Hedera, the distributed-ledger network governed by a council that includes Google, IBM, Deutsche Telekom and a rotating cast of enterprise members. Hedera has spent years positioning itself as the enterprise-friendly alternative to Ethereum: predictable fees, deterministic finality, governance by known institutions. Friday's exploit did not break Hedera's consensus. It did, however, expose that the application layer built on top of Hedera inherits the same oracle risk as every other chain.

That distinction matters less to users who lost funds than the broader narrative suggests. From the outside, an exploit on Hedera is an exploit on Hedera. The technical location of the bug inside an oracle contract rather than inside a ledger node is a footnote to anyone trying to recover their position.

For Hedera's institutional pitch, though, the timing is awkward. The network has been quietly accumulating DeFi liquidity through protocols such as Bonzo, SaucerSwap, and the HeliSwap aggregator, on the bet that enterprise-grade governance would eventually attract institutional credit markets. A 77 percent value-locked wipeout in one of its flagship lending markets undercuts that pitch, at least until a clean post-mortem is published.

What is contested, and what comes next

Several details remained unsettled at the time of writing. CoinDesk's forensic reporting attributes the loss to roughly $9.05 million and to a flaw in Supra's verifier; Cointelegraph's initial wire converges on the same mechanism but a slightly lower headline figure. Neither outlet had, by mid-afternoon UTC, reported any public statement from Supra acknowledging the specific verifier flaw, nor any commitment from Bonzo's team on a treasury plan to cover user losses. Monexus has not independently verified the on-chain movements and is relying on the two wire reports above.

The harder question is whether the broader DeFi lending complex is going to absorb this episode or shrug it off. The historical pattern is shrugs: each successive oracle exploit produces a wave of post-mortems, a brief push toward decentralised oracle networks, and a slow drift back to whatever feed is cheapest. Friday's episode is unlikely to break that pattern unless a credible protocol publicly adopts multi-oracle redundancy as a baseline requirement and is willing to pay the latency and capital costs that come with it.

For now, the practical takeaway for users is the same one that follows every oracle exploit: read the fine print on which feed your market trusts, assume that feed is a single point of failure, and size positions accordingly. Until lending markets start treating the oracle layer as critical infrastructure rather than commodity plumbing, the next Bonzo is a matter of when, not if.


Desk note: the wire coverage so far is forensic, not editorial. Monexus treats both CoinDesk's and Cointelegraph's numbers as provisional pending Supra's own statement; the 77 percent value-locked figure comes from CoinDesk's market-data read and may move as withdrawals settle.

Intelligence ThreadFollow on terminal ↗
© 2026 Monexus Media · AI-native reporting from public-source material