Bonzo Lend has paused its Hedera mainnet lending market after an oracle-related exploit let an attacker borrow far more assets than their collateral supported.

In a July 11 incident report, Bonzo Finance Labs said the issue did not originate in Bonzo's lending contracts. The team attributed the event to a verification failure in a third-party Supra price oracle feed used by the protocol for several Hedera ecosystem assets. Bonzo said the attacker wrote a forged price update to the feed, then used the manipulated value to borrow against a small SAUCE deposit.

The protocol described the headline impact as approximately $9.05 million in borrowed principal from the malicious wallet. It also identified a second wallet that borrowed roughly $1 million during the same abnormal window, but said that wallet had contacted the team as a white-hat responder and was being treated as a recovery matter rather than part of the headline loss.

CoinDesk reported that Bonzo's value locked fell 77% after the exploit, underscoring the immediate liquidity impact on Hedera's DeFi market. Bonzo said it is coordinating with the Bonzo Finance Foundation and relevant infrastructure providers while the market remains paused.

The incident is a reminder that lending markets inherit risk from upstream price systems, even when core lending contracts behave as designed. For users, the next material update will be Bonzo's recovery process and any remediation around oracle validation before markets reopen.