Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add to Google Preferred Sources
Bonzo Lend, a decentralized finance lending protocol built on Hedera, suffered approximately $8.7 million in losses from a price manipulation attack that exploited a vulnerability in the Supra oracle service. The attacker deposited 250 SAUCE tokens as collateral, then inflated their price by nearly a trillion-fold to drain 6.63 million USDC and 34.5 million wHBAR from the lending pool. The incident extends a surge in DeFi hacks throughout 2026, with recurring security breaches driving total value locked down 39% from the start of the year. A similar oracle manipulation attack struck Stellar-based YieldBlox DAO in February, resulting in a $10 million theft.
Key Elements

Hedera-based decentralized finance (DeFi) lending protocol Bonzo Lend suffered approximately $9 million in losses — roughly 13 billion won (approximately $8.7 million) — from an oracle price manipulation attack. According to a preliminary incident report released on the 11th, the attacker successfully manipulated the price of a collateral asset to borrow far more than its actual value.
Bonzo Lend attributed the incident to a flaw in the oracle service Supra. The report indicates the attacker deposited just 250 SAUCE tokens — worth only a few dollars — as collateral, then inflated the SAUCE price feed delivered to on-chain oracle validators by approximately one trillion times. Based on the manipulated price, the attacker proceeded to withdraw 6.63 million USDC and 34.5 million wrapped HBAR (wHBAR) from the lending pool.
Bonzo Lend emphasized in its incident report that “this exploit was not due to a vulnerability in Bonzo Lend’s smart contracts or the Hedera core network.” The protocol stated that Supra identified a flaw in its oracle validator that accepted manipulated prices with missing signatures and immediately deployed a corrective patch.
The incident comes amid a sharp rise in security breaches targeting DeFi protocols. According to CryptoRank data, 121 hacks have occurred in 2026 to date, with total losses reaching approximately $942 million. The second quarter alone recorded 83 exploits — the highest quarterly count on record — resulting in roughly $755 million stolen. Cross-chain bridge exploits accounted for $351 million of that total, while admin account takeovers and fake token price manipulation attacks represented 37% of quarterly losses.
Recurring security incidents are weighing heavily on investor sentiment. DeFi total value locked (TVL) plummeted 39%, from approximately $115 billion in January 2026 to below $70 billion as of June. CryptoRank noted that the string of security breaches has eroded user trust and accelerated capital outflows.
A similar oracle price manipulation attack previously occurred on the Stellar network. In February, attackers manipulated the price path of USTRY collateral in a lending pool managed by YieldBlox DAO, stealing approximately $10 million in assets. That incident likewise involved loans that far exceeded the actual value of the collateral.
The Bonzo Lend case demonstrates that even when the application and underlying network are functioning normally, a single oracle flaw can transform low-value collateral into a vehicle for draining massive liquidity. The incident has once again underscored the critical importance of oracle infrastructure in ensuring the integrity of on-chain price data across the DeFi industry.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com
