Hedera lending protocol Bonzo loses roughly $9 million in oracle exploit
An attacker inflated the value of SAUCE collateral through a third-party oracle flaw and walked away with about $9 million, knocking 77% off Bonzo Lend's locked value in hours.

The drain happened in minutes. On 11 July 2026, an attacker exploited a verification flaw in a Supra oracle contract on Hedera, inflated the value of SAUCE collateral, and walked out of the Bonzo Lend lending pool with roughly $9.05 million, according to two separate wire reports filed that day. The protocol's total value locked fell by about 77% as users rushed for the exits and the market quietly repriced what "trustless" infrastructure actually means.
The incident is the latest reminder that in decentralised finance the weakest link is rarely the chain itself. Hedera's mainnet kept producing blocks throughout the attack; the failure sat in the price-feed layer Bonzo rented from a third party, the kind of plug-and-play plumbing that lets a small team launch a money market without running its own oracle network. The trade-off for that convenience, made visible in dollar terms, is roughly nine million dollars.
What the attacker actually did
The exploit hinged on SAUCE, the governance and utility token of the SushiSwap-derived decentralised exchange that anchors much of Hedera's DeFi activity. According to CoinDesk, the attacker manipulated Bonzo's reliance on Supra's on-chain price verifier, presenting collateral at an inflated mark and borrowing against it. CoinTelegraph's reporting on the same day put the losses at about $9 million and pointed to a flaw in Supra's verifier contract rather than Bonzo's own code.
That distinction matters for who pays. Lending protocols typically socialise losses across depositors when borrowed assets cannot be recovered; in Bonzo's case the haircut has shown up directly in the TVL chart, which collapsed by roughly three-quarters within hours of the transaction settling. Liquidations paused, withdrawals thinned out, and SAUCE itself traded down sharply on the residual panic.
The mechanics follow a familiar pattern: a thin-pool token, a single third-party price feed, a verifier that trusted a number it should have weighted. The novel element here is the chain. Hedera has marketed itself as the enterprise-grade, hashgraph-powered alternative to the EVM ecosystem where most oracle exploits are documented. The Bonzo incident is the first headline-scale oracle attack against a Hedera-native lending market, and it landed on a network whose pitch to institutional users rests on deterministic finality and predictable behaviour.
The Supra oracle angle
Supra, the oracle provider whose verifier was compromised, operates across more than a dozen chains and is one of several multi-chain price-feed networks competing for the same integrator slot that Chainlink has held since the early DeFi cycles. On Hedera specifically, Supra had become a near-default reference for protocols that did not want to bootstrap their own price-discovery infrastructure. That concentration made the flaw systemic in a way Bonzo's own audit posture was not.
The reporting does not yet say whether Supra paused the affected verifier contract, whether a bug bounty is involved, or whether the team has named the precise signature of the exploit. The cautious reading is that an oracle provider is rarely in a hurry to publish a post-mortem while funds are still being traced across chains. A more sceptical reading, worth keeping on the table, is that the verifier contract may have been acting within its specification under extraordinary conditions rather than failing inside it; that is, the bug may be economic rather than cryptographic, and the fix may live in how protocols cap exposure to any single feed.
Hedera's own communications around the incident have so far centred on continuity of the underlying network. That is technically accurate and strategically incomplete. The reputational damage from an oracle exploit accrues to the chain where the lost dollars were deposited, irrespective of where the code that failed was hosted.
Counterpoint: not every oracle attack is a chain verdict
The dominant framing writes this episode as a Hedera story. A fair counter-read: it is a Bonzo story wearing Hedera skin. Oracles are shared infrastructure, and the protocols that integrate them make an active choice about which feeds they trust, how they aggregate them, and how they cap loan-to-value ratios against thin-float tokens. A protocol that relied on a single Supra feed for SAUCE without circuit-breakers, sanity bounds, or cross-checks against a second oracle made a stack-of-cards bet that any auditor would flag.
The structural lesson for the rest of Hedera's DeFi corner is the same one Ethereum's DeFi corner learned after each major oracle exploit of the 2020s: diversify the feed, bound the exposure, and assume that any single price source can be wrong on the worst possible afternoon. None of that rebuilds the nine million dollars Bonzo's users lost this weekend. It does, however, set the terms on whether the next exploit on Hedera produces a similar headline.
What is still unknown
The wire reporting is consistent on the headline number and the named protocol but light on three things that will decide what kind of story this becomes. First, the recovery path: it is not clear whether Bonzo has bad-debt reserves, a treasury, or insurance coverage sufficient to make depositors whole, or whether losses will be socialised. Second, the forensic question of whether the same exploiter has footprint on other chains; Supra-integrated protocols on EVM networks will want that answer soon. Third, the regulatory question, which is harder: SAUCE and hbar trade in jurisdictions where DeFi protocols remain in a legal grey zone, and a nine-figure-style loss in dollar terms draws interest even when the protocol itself is small.
What Monexus found reporting this piece: the headline number holds across two independent wires; the failure point is named consistently; the TVL collapse is the cleanest tell that depositors are voting with their feet. What the sources do not specify yet is who, if anyone, ends up reimbursing the bag-holders, and whether Supra's verifier gets patched quietly or under a coordinated disclosure.
Desk note: Monexus treated the Bonzo loss as a protocol-and-oracle story first, and as a Hedera story second. The dominant wire framing will foreground the chain; the structural lesson sits in the shared infrastructure layer underneath it.