Bonzo Lend protocol, the largest lending platform in the Hedera ecosystem, experienced a cyberattack that reportedly caused losses of around $9.05 million after an exploit in an external pricing system (Oracle).

The attacker leveraged a flaw in the price data validation, allowing them to submit an inflated price for the SAUCE token that exceeded its real value by several orders of magnitude. As a result, they were able to use a small amount of the token as collateral to borrow assets worth vastly more than their actual value.

Bonzo’s team confirmed that the platform’s smart contracts were not the cause of the breach; the issue stemmed from the external pricing data provider, which failed to reject the falsified data.

Following the incident, the lending services were temporarily suspended, while investigations continue and efforts to recover funds and compensate users are underway. One participant in the operation, who identified himself as a security researcher (White Hat), also announced his readiness to return a portion of the withdrawn assets.

🔹 What do you think? Have decentralized lending protocols become overly reliant on external data providers, or are incidents like this a natural part of DeFi’s evolution?