Odaily Planet Daily reports: Bonzo Finance, a lending protocol built on Hedera, suffered an oracle attack resulting in losses of approximately $9 million. The attacker exploited collateralized SAUCE tokens whose price was artificially inflated to borrow assets far exceeding their actual value. According to Bonzo Finance’s preliminary incident report, the attacker deposited only 250 SAUCE tokens, then submitted a single price update that artificially inflated the token’s price by approximately 12 orders of magnitude, subsequently borrowing 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool.
This attack was not due to a vulnerability in Bonzo Finance’s smart contract or the underlying Hedera network, but rather stemmed from a flaw in Supra’s on-chain oracle validator, which incorrectly accepted a SAUCE price data feed with a zeroed-out signature. Supra has since confirmed the issue and completed the fix.
