Kitto@kitto
Crypto Trading
Bonzo Lend, the largest lending protocol in the Hedera ecosystem, has lost approximately $9.05 million in assets due to an oracle vulnerability exploit. Fortunately, this attack did not stem from a smart contract flaw within Bonzo Lend itself, but rather from a signature verification error in Supra, the oracle solution providing price feeds.
The attacker exploited a loophole where the Supra oracle incorrectly accepted an empty zero signature [0,0] as valid. This allowed them to artificially inflate the price of SAUCE, the native token of SaucerSwap, by nearly a trillion times. After depositing just 250 SAUCE—worth only a few dollars—as collateral, the attacker exploited the abnormally spiked value to "borrow" and drain 6.63 million USDC and 34.5 million HBAR, which were then bridged to the Ethereum chain.
In the wake of this incident, major South Korean exchanges such as Upbit, Bithumb, and Coinone immediately issued investment warning alerts for Hedera (HBAR). Fortunately, there is a potential for partial recovery; another wallet owner who took approximately $1 million announced on Discord that they are a white hat hacker and intend to return the funds. Supra also stated that they have completed an on-chain patch to fix the bug, eliminating the risk of further damage.
This is a bitter reminder that even if a protocol's code is secure, the entire ecosystem can be shaken by a single external data stream. This is why when using DeFi, you must carefully check not only the protocol's own audit reports but also which oracle they are using.
Related links