Bonzo Lend, a lending protocol on the Hedera network, has lost approximately $9 million in a sophisticated oracle exploit that allowed an attacker to manipulate a single price feed and drain funds from the platform in seconds. The exploit is the latest in a recent spate of oracle manipulation attacks affecting DeFi protocols.
According to security analysts, the attacker manipulated a Supra Oracle price feed, turning approximately 250 SAUCE tokens worth a few dollars into $9.05 million in borrowed USDC and wrapped HBAR. The entire exploit occurred within eight seconds, highlighting the speed at which automated DeFi attacks can be executed.
Supra, the oracle provider, had reportedly patched similar vulnerabilities on 11 other blockchain networks before the Hedera exploit occurred. The timing of the attack suggests the vulnerability on Hedera may have been identified and exploited before the patch could be applied to that network.
The exploit is part of a troubling trend of oracle manipulation attacks in the DeFi sector. Earlier the same week, the Ostium protocol lost up to $18 million in a similar oracle exploit that exploited registered price-feed forwarders and future-dated oracle reports to book fraudulent trading profits.
Security firms have urged DeFi protocols to implement multiple redundant oracle sources, circuit breakers for sudden price movements, and real-time monitoring for suspicious oracle activity. The cumulative losses from oracle manipulation attacks in 2026 have already exceeded hundreds of millions of dollars.
