security
Lending protocol Bonzo loses 77% of value locked as $9 million oracle exploit rattles Hedera
Bonzo Lend lost approximately $9.05 million after an attacker exploited a verification flaw in a third-party oracle contract on the Hedera network.
AS1 NewsSource: coindesk.com
Bonzo Lend, a lending protocol operating on the Hedera network, experienced a major security incident resulting in a loss of about $9.05 million. The breach was caused by an attacker exploiting a flaw in the verification process of a third-party Supra oracle contract. Oracles are crucial in DeFi as they provide external data needed for smart contract operations, such as price feeds.
The attacker identified and exploited a vulnerability in the oracle's verification mechanism, which allowed them to manipulate the data fed into the protocol. This manipulation led to a significant reduction in the total value locked (TVL) in Bonzo Lend, which dropped by approximately 77%. The incident highlights the risks associated with reliance on third-party oracles in DeFi protocols.
The event underscores the importance of robust security measures for oracles and external data sources in decentralized finance. It also raises concerns about the security practices of protocols that depend heavily on third-party services for critical functions.
While the direct impact is on Bonzo Lend and its users, the incident may also influence the broader Hedera ecosystem and other DeFi projects that utilize similar oracle services. It emphasizes the need for improved security and verification processes in oracle implementations.
The security breach resulted in a significant loss of funds and a sharp decline in protocol value, highlighting vulnerabilities in oracle security within DeFi.