security
Bonzo Lend Loses $9M in Hedera Oracle Exploit
Bonzo Lend, a lending protocol on Hedera, lost approximately $9.05 million after an attacker exploited a flaw in a third-party Supra oracle contract. The attacker manipulated a price feed to borrow large amounts of USDC and wrapped HBAR with minimal collateral.
AS1 NewsSource: thedefiant.io
Bonzo Lend, a decentralized lending platform operating on the Hedera network, suffered a significant security breach resulting in a loss of around $9.05 million. The attack occurred on July 11 when an attacker exploited a verification flaw in a third-party Supra oracle contract. Using a manipulated price feed, the attacker deposited just 250 SAUCE tokens, worth only a few dollars, as collateral and quickly borrowed substantial amounts of USDC and wrapped HBAR within eight seconds.
The exploit was made possible due to vulnerabilities in the oracle's price verification process, allowing the attacker to manipulate the data fed into the protocol. This manipulation enabled the attacker to borrow far more than the collateral was worth, leading to the large loss for Bonzo Lend.
Oracle vulnerabilities have been a recurring issue in DeFi, often exploited to manipulate prices and drain funds. In this case, the flaw was in a third-party oracle service, highlighting the risks associated with relying on external data sources for critical protocol functions.
The incident underscores the importance of robust oracle security and verification mechanisms in DeFi protocols, especially on emerging networks like Hedera. It also raises concerns about the safety of cross-chain and third-party oracle integrations.
While the event does not directly impact the Hedera blockchain itself, it may influence user confidence in DeFi protocols on Hedera and similar networks, emphasizing the need for improved security measures in oracle implementations.
The exploit highlights vulnerabilities in oracle security, which could lead to increased scrutiny and improved safeguards in DeFi protocols.