Price Oracle Flaw Leads to $9 Million Drain on Hedera DeFi Platform
An attacker exploited a vulnerability in a price oracle to steal millions from Bonzo Lend, highlighting ongoing DeFi risks.

A decentralized lending protocol built on the Hedera network has suffered a significant exploit, losing approximately $9 million after an attacker manipulated a price oracle. The incident, which targeted Bonzo Lend, underscores persistent vulnerabilities in how DeFi platforms handle external data feeds.
How the Exploit Unfolded
The attacker reportedly abused a flaw in the protocol's oracle mechanism, which is responsible for fetching real-world asset prices on-chain. By feeding manipulated price data, they were able to borrow assets far exceeding their collateral, draining the platform's liquidity pools before the anomaly was detected.
Key aspects of the attack include:
- Manipulation of a single price feed to create false collateral valuations
- Rapid borrowing and withdrawal to maximize the stolen amount
- Exploitation of a lag in the protocol's oracle update mechanism
Bonzo Lend has paused its markets while the team investigates and works on a recovery plan. The Hedera network itself was not compromised, but the incident raises questions about the security of DeFi applications that rely on oracles.
This is not an isolated event. Similar oracle attacks have drained millions from other platforms in the past, reinforcing the need for more robust data feeds, multiple oracle sources, and real-time anomaly detection. As DeFi continues to grow, the arms race between attackers and developers shows no signs of slowing down.

