DeFi Protocol Loses $9M in Oracle Manipulation Attack

The DeFi ecosystem on Hedera faced a significant security breach this week. Bonzo Finance, a lending protocol built on the network, suffered an attack resulting in approximately $9 million in losses. The incident highlights persistent vulnerabilities in decentralized finance's underlying infrastructure.

How the Attack Unfolded: A Price Manipulation Scheme

The exploit occurred on July 11th. The attacker deposited a small amount of SAUCE tokens as collateral, then manipulated the price feed for that asset through the protocol's oracle system.

  • Price Inflation: SAUCE's reported value was artificially inflated by about 12 orders of magnitude
  • Excessive Borrowing: Using the inflated collateral value, the exploiter borrowed 6.63 million USDC and 34.5 million wHBAR (wrapped HBAR)
  • Asset Extraction: The borrowed funds were quickly withdrawn and converted, creating the actual financial loss

Root Cause: Third-Party Oracle Vulnerability

Bonzo's preliminary investigation indicates the protocol's smart contracts and Hedera's base network were not compromised. Instead, the weakness existed in the oracle service provided by Supra.

Supra's on-chain oracle verifiers incorrectly accepted a SAUCE price data packet with a zeroed signature field. This validation flaw allowed the attacker to feed false price information to the protocol. Supra has since confirmed and fixed the technical issue.

Broader Implications for DeFi Security

This event underscores the critical role and vulnerability of oracle services in DeFi. Even protocols with thoroughly audited code can be compromised through their external data dependencies.

Many projects are now reevaluating their oracle security configurations, considering measures like multi-source price verification, anomaly detection systems, and time-delay mechanisms. For users, diversifying exposures and understanding protocol risk factors remain essential practices when engaging with DeFi platforms.