Bonzo Lend, a lending protocol on the Hedera network, suffers an approximately $9 million loss after an attacker exploits an oracle verification flaw connected to token pricing. Multiple outlets report that the attacker manipulates the price of the SAUCE token, allowing the attacker to borrow assets far exceeding the value of collateral deposited in the protocol. The exploit is traced to a problem in Supra’s on-chain oracle verification system, where the manipulated SAUCE price is accepted for lending calculations.
CoinDesk reports the loss as about $9.05 million, while other sources describe the exploit amount as roughly $9 million. NDTV and CoinDesk add that Supra has patched the vulnerability. NDTV also states that Bonzo Lend and Hedera say their core smart contracts and blockchain infrastructure are not compromised, indicating the incident is confined to the third-party oracle verification logic used for pricing.
Overall, the reports align on the mechanism (SAUCE price inflation via oracle manipulation), the affected lending protocol (Bonzo Lend), and the approximate scale ($9 million), with remediation focused on fixing the oracle verification flaw.