Bonzo Lend published an incident report after a Hedera mainnet exploit that allowed an attacker to borrow far beyond available collateral. The team said the issue came from a third-party price oracle layer, not from Bonzo Lend’s own smart contracts. Bonzo Lend and Points were paused, while Bonzo Vaults, Bridge and staking were listed as unaffected. External coverage put the loss at about $9 million.

The lesson is that lending risk does not stop at audited contracts. A protocol can be technically intact and still fail if the price path feeding collateral values is manipulated. The second-order risk is confidence leakage: users may distrust connected products even when they were not directly affected.

Next, watch the recovery plan, oracle changes and whether affected users receive a clear compensation process.