Bonzo Lend Exploited for $9.05 Million via Oracle Vulnerability
Bonzo Lend experienced a significant exploit resulting in a loss of $9.05 million. The attack involved a manipulated price from a third-party oracle, allowing for large asset borrowing with little collateral.
The exploit occurred on July 11, 2026, when an attacker took advantage of a vulnerability in the Supra oracle used by Bonzo Lend. By submitting a manipulated SAUCE price, the attacker was able to borrow approximately $9.05 million in assets with minimal collateral.
Following the exploit, the borrowed funds were swapped on SaucerSwap and bridged to Ethereum using LayerZero, with over $5 million tracked on-chain. In response to the abnormal activity, Bonzo Lend paused the protocol to mitigate further losses.