
A security breach in Bonzo Lend, a major lending platform on Hedera, allowed an attacker to steal nearly $9 million on July 11. This incident has sparked outrage in the community over the integrity of third-party oracles like Supra, raising concerns about security frameworks in the decentralized finance space.
The exploit began when Wallet A deposited just 250 SAUCE tokens and quickly manipulated the system. By inflating the price for the SAUCE/wHBAR trading pair to an absurd level, the attacker borrowed 6,634,528 USDC and 34,518,389 wHBARβyeah, a whopping $9 million in mere seconds.
"A large price swing should have alerted something," remarked one community member.
The underlying issue lay in the oracle's failure. Despite Bonzo operating as intended, the on-chain verifier for the Supra price feed did not reject the zeroed signature input. Investigators express dismay that the oracle trusted the wrong answer to the right question.
Forum responses illustrate a mix of frustration and disbelief. Users are calling for better risk controls and express skepticism about the choice of oracle. One commenter questioned:
"Why not use Chainlink? They use Supra because it is cheaper, but why have Chainlink as a council member?"
Some comments highlight the importance of implementing oracle redundancy. Suggestions include utilizing several oracles to mitigate risks and better secure the lending protocol.
Incident Timestamp: The attack started at 00:51 UTC.
Price Restoration: Correct pricing was reestablished by 01:36 UTC.
Protocol Pause: Bonzo Lend was paused within minutes at 01:41 UTC.
Interestingly, a second account, Wallet B, also exploited the gap, borrowing about $1 million. This individual identified themselves as a white-hat hacker and expressed willingness to return the funds, which Bonzo Labs is treating as a recovery issue.
Developers at Bonzo Finance Labs have confirmed the issue does not stem from their smart contracts and are implementing fixes. Meanwhile, Bonzo Vaults and other services remain operational. The incident has triggered discussions around enhancing security protocols not just for Bonzo but across the DeFi landscape.
β οΈ Attack exploited the oracles' flaw, resulting in a $9 million loss.
π Community calls for reassessment of oracle risk controls.
πΌ Recovery strategies under discussion as developers aim to restore confidence.
As the investigation develops, one has to wonderβhow can decentralized platforms reinforce security measures to avert such incidents in the future? In the wake of this exploit, many in the community are pushing for immediate reforms.
The $9 million heist serves as a stark reminder of vulnerabilities within decentralized finance, putting pressure on developers to bolster their defenses against future threats.