Root Cause: Oracle Manipulation
Published 7/11/2026, 9:09:31 PM
The $5.25 million exploit on July 11, 2026, was caused by a protocol-level oracle manipulation attack targeting Bonzo Finance, a decentralized lending protocol on the Hedera network. The attacker artificially inflated the price of the SAUCE token to borrow excessive amounts of USDC and HBAR, subsequently bridging the stolen assets to Ethereum via LayerZero.
Root Cause: Oracle Manipulation
The exploit did not involve a breach of Hedera’s core infrastructure or validator keys. Instead, the attacker manipulated the SAUCE token price oracle on the SaucerSwap decentralized exchange (DEX), which Bonzo Finance used as its primary price feed.
- Mechanism: By manipulating the SAUCE price on SaucerSwap, the attacker made their collateral appear significantly more valuable than its actual market price.
- Assets Drained: This allowed the attacker to borrow approximately 6.6 million USDC and 35 million HBAR from Bonzo Finance.
- Preparation: The attacker's wallet was initially funded with 1 ETH from Tornado Cash to cover transaction fees while masking the source of the funds.
Fund Flow and Destination
After draining the protocol, the attacker moved the assets through a series of swaps and cross-chain transfers to consolidate the loot on the Ethereum mainnet.
- DEX Swaps: Stolen HBAR and USDC were swapped for liquid assets on SaucerSwap.
- Cross-Chain Bridging: The attacker used the LayerZero bridge to move the funds from Hedera to Ethereum.
- Consolidation: The stolen value was consolidated into a single Ethereum wallet:
0x2fd2a8d39fd7c4751fea109a86fa4cdd989e6ad3. - Final Asset Composition: The funds were converted into approximately 2,068–2,284 ETH (valued at
$3.7M–$4.1M) and 15.58 WBTC ($1M).
Impact Summary
| Metric | Details |
|---|---|
| Total Loss | ~$5.25 Million |
| Primary Target | Bonzo Finance (Lending Protocol) |
| Attack Vector | Oracle Manipulation (SAUCE/USDC pair) |
| Attacker ETH Address | 0x2fd2a8d39fd7c4751fea109a86fa4cdd989e6ad3 |
| HBAR Price Impact | Dropped 3.5% to 5% following the news [Source: https://x.com/cryptothedoggy/status/2076033881749471319] |
The exploit caused immediate market volatility, with HBAR erasing recent gains and testing support levels near $0.066 shortly after the incident was reported [Source: https://x.com/cryptothedoggy/status/2076033881749471319]. While the funds have been consolidated on Ethereum, they remain in the attacker's wallet as of the latest research data.