Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Bonzo Lend Oracle Exploit Triggers Cross-Chain Fund Transfers on Hedera

A manipulated SAUCE oracle price enabled an attacker to borrow about $9.05 million from Bonzo Lend before part of the assets was moved from Hedera to Ethereum.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
July 11, 2026
in Security & Hacks
0 0
Suspected Hedera DeFi Hack Moves $5.8 Million to Ethereum

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A Bonzo Lend oracle verification exploit allowed an attacker to borrow approximately $9.05 million using a manipulated SAUCE price before part of the extracted assets was moved from Hedera to Ethereum. The incident was first detected through cross-chain fund movements and was initially reported as a suspected Hedera DeFi hack.

On-chain investigator Specter initially reported that millions of dollars in assets were being bridged from Hedera to Ethereum through LayerZero, with some wrapped Bitcoin later converted into ETH. Bonzo Finance subsequently confirmed that the affected application was Bonzo Lend and attributed the incident to a flaw in a third-party oracle’s verification process. Bonzo estimated that the primary attacker borrowed approximately $9.05 million after submitting a manipulated price for the SAUCE token. The protocol said its lending contracts and Hedera’s underlying consensus network were not compromised

There appears to be an ongoing hack involving @hedera Network, with over $3.7M already bridged to Ethereum by the attacker.

The stolen funds are currently being swapped from WBTC for ETH after being bridged from the Hedera network via Layerzero.

Theft addresses:… pic.twitter.com/KSxd3K2vlu

— Specter (@SpecterAnalyst) July 11, 2026

Funds Bridged and Converted to ETH

Specter identified two Ethereum addresses linked to the early cross-chain movements:

  • 0x9A4966152F6e10b33Cb7a37975e8619816d6a494
  • 0xaf20D792A19fD42dCf697ceBa6100291D96dD93e

The initial estimate of funds moved to Ethereum rose as additional transactions were detected. The receiving wallets held ETH and WBTC, while portions of the wrapped Bitcoin were exchanged for ETH after crossing the network. LayerZero appears to have served as the route used to bridge the assets rather than the source of the vulnerability. Bonzo’s incident report also said its separate bridge product was not affected and continued operating normally.

Cross-chain movements remain important in post-exploit investigations because attackers can divide, exchange or obscure assets after leaving the original network. The Kelp DAO case showed how stolen funds can be rapidly routed through services such as THORChain, Tornado Cash and Bitcoin privacy tools, leaving only a small portion directly traceable. No comparable laundering route had been confirmed in the Bonzo incident during the initial tracking period. The bridge activity represented only part of the wider economic impact, which Bonzo later calculated from the assets borrowed from its lending pool.

Manipulated SAUCE Price Enabled Excessive Borrowing

According to Bonzo, the exploit began at approximately 00:51 UTC on July 11, when the attacker submitted a manipulated SAUCE price to an on-demand oracle contract on Hedera. SAUCE was trading at roughly 0.2 HBAR, but the malicious update inflated the token’s value by around 12 orders of magnitude. The oracle verifier accepted the update even though it contained a zeroed signature rather than a valid signature from the authorised oracle committee.

The @bonzo_finance lend protocol has been temporarily paused.

The Bonzo Finance Labs team is investigating volatile markets across Bonzo Lend and diligently working alongside partners during this investigation.

The team will continue to provide updates as they become…

— Bonzo Finance Labs (@bonzo_finance) July 11, 2026

Eight seconds after the false price was recorded, the attacker used a deposit of 250 SAUCE, worth only a few dollars, as collateral to borrow:

  • Approximately 6.63 million USDC
  • More than 34.5 million WHBAR

Bonzo said the verifier incorrectly approved the submission because both the signature point and the referenced committee public key resolved to zero, allowing the cryptographic check to return a valid result. The incorrect price remained active until legitimate oracle publishing restored SAUCE to about 0.1964 HBAR at 01:36 UTC. Bonzo Lend was paused five minutes later.

The protocol identified Supra as the oracle provider whose verification infrastructure accepted the invalid update. Bonzo said Supra acknowledged the issue and deployed a fix to the affected verifier contract on Hedera mainnet.

Bonzo Places Primary Impact at $9.05 Million

Bonzo calculated the principal borrowed by the malicious wallet at approximately $9.05 million, based on an HBAR reference price of $0.06998 and USDC valued at $1. A second wallet borrowed roughly $1 million while the manipulated price remained active. That wallet later contacted Bonzo, identified itself as a white-hat responder and stated that it intended to return the assets. Bonzo excluded this amount from its headline impact figure, although total borrowing during the abnormal pricing period reached approximately $10.06 million.

The incident adds to a wider increase in operational and infrastructure-related security risks across Web3. Crypto projects lost about $1.31 billion across 344 incidents during the first half of 2026, with attackers increasingly targeting privileged access, key management and supporting infrastructure alongside smart-contract vulnerabilities. Bonzo cautioned that the $9.05 million estimate represents borrowed principal rather than a final loss calculation. It does not include interest, transaction fees, subsequent swaps, market-price changes or any assets later recovered.

Bonzo Lend and Bonzo Points remain paused while the team evaluates recovery and withdrawal plans. Bonzo Vaults, Bonzo Bridge and single-sided BONZO and XBONZO staking were not affected and continued operating normally. The official findings clarify that the incident was an oracle verification exploit affecting Bonzo Lend, not a compromise of Hedera’s consensus network or LayerZero. Recovery efforts and reimbursement plans are expected to be addressed in later updates.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto HacksDeFi
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed
Security & Hacks

Three Cosmos EVM Chains Halt After a Flaw Cosmos Labs Already Called Fixed

by Saravana Kumar Mahendran
August 25, 2026

Cosmos Labs asked every Cosmos EVM chain in contact with it to halt validators on August 24 during an ongoing...

Read moreDetails
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026

BounceBit Shuts Down Its Blockchain After Exploit Drains a Quarter of BB’s Circulating Supply

August 22, 2026
MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability

MANTRA Chain Halts Network After Confirming Attacker Exploited Upstream Vulnerability

August 21, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain’s Old Playbook

Maya Protocol Hack: Why the Recovery Plan Mirrors THORChain’s Old Playbook

August 19, 2026
Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

August 14, 2026
Next Post
BingX Launches the BingX Visa Debit Card, Bridging Digital Assets and Everyday Payments

BingX launches the BingX Visa Debit Card, bridging digital assets and everyday payments

Crypto Token Vesting Slows This Week as 31 Projects Prepare $68.29M in Scheduled Unlocks

Crypto Token Vesting Slows This Week as 31 Projects Prepare $68.29M in Scheduled Unlocks

Recommended

  • All
  • Crypto News Today
Grayscale’s Zcash ETF Bet: Fixing Years of Mispricing, Not Just Adding Access

Grayscale’s Zcash ETF Bet: Fixing Years of Mispricing, Not Just Adding Access

August 25, 2026
Kinetiq's Elysium L2 Turns Hyperliquid Trading Fees Into KNTQ Buybacks

Kinetiq’s Elysium L2 Turns Hyperliquid Trading Fees Into KNTQ Buybacks

August 25, 2026
Monad Proposes Wallet Upgrade for Key Recovery and Quantum Security

Monad Proposes Wallet Upgrade for Key Recovery and Quantum Security

August 25, 2026
US Treasury Expands Iran Crypto Sanctions Authority Over $100M in Payments

US Treasury Expands Iran Crypto Sanctions Authority Over $100M in Payments

August 25, 2026
X’s promise of crypto trade buttons is at least its third since January

X’s promise of crypto trade buttons is at least its third since January

August 25, 2026
Visa Partners With Nium to Trial Seven-Day Stablecoin Settlement in Singapore

Visa Partners With Nium to Trial Seven-Day Stablecoin Settlement in Singapore

August 25, 2026
Las Vegas man convicted in $24M crypto Ponzi scheme, his second SEC case

Las Vegas man convicted in $24M crypto Ponzi scheme, his second SEC case

August 25, 2026
BNB Chain Goes Live With Pasteur Hard Fork Upgrade

BNB Chain Goes Live With Pasteur Hard Fork, Boosting Bridge Security

August 25, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Shipyard to End All IPFS Maintenance Sept. 30 After Protocol Labs Cuts Funding
  • Grayscale’s Zcash ETF Bet: Fixing Years of Mispricing, Not Just Adding Access
  • Kinetiq’s Elysium L2 Turns Hyperliquid Trading Fees Into KNTQ Buybacks

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.