The Hedera-based lending protocol remains paused after about $10.06 million in abnormal borrowing, including roughly $1 million from a wallet that said it would return the funds.
Bonzo Lend, a lending protocol on Hedera, remains paused after an attacker exploited a verification flaw in a third-party Supra oracle contract on July 11, allowing about $10.06 million in abnormal borrowing before any recovery. One wallet used 250 SAUCE worth only a few dollars as collateral, pushed through a manipulated SAUCE price update, and then borrowed 6.63 million USDC and 34.52 million wrapped HBAR, worth about $9.05 million at the report’s reference HBAR price. A second wallet borrowed roughly $1 million more while the distorted price remained active, then contacted Bonzo on Discord, identified itself as a white-hat responder and said it would return the funds. Bonzo had previously counted that amount as potentially recoverable, but the protocol remains paused pending recovery work. Supra Labs said the failure stemmed from a degenerate BLS signature and zero-valued public key that its Hedera verifier incorrectly accepted for a single SAUCE/wHBAR feed, while saying its core aggregation and other feeds were unaffected. The exploit triggered broader fallout across Hedera DeFi: the network’s total value locked fell nearly 40% over 24 hours, Bonzo’s TVL dropped 77% in the same period, and DefiLlama now shows Bonzo’s TVL at $3.06 million. A security researcher’s technical writeup said more than $5.25 million of the stolen funds was bridged to Ethereum via LayerZero and swapped into ETH within hours.