USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

Bonzo Lend on Hedera Loses About $9M to Oracle Bug: What U-Card Users Should Note

2026-07-19

According to Tokenpost, citing a Protos report, the lending protocol Bonzo Lend on the Hedera (HBAR) network was attacked over the weekend, with losses reported at around $9 million. Per the report, the attacker exploited a flaw in an oracle price feed to artificially inflate collateral value, then borrowed far more than the collateral was actually worth. The report further states that the issue traces back to an oracle provided by infrastructure vendor Supra Network — Supra had reportedly patched oracles across several chains recently, but the Hedera contract was allegedly missed, ultimately becoming the target.

To be clear: the dollar figure and the “patched multiple chains but missed Hedera” causal claim currently come from secondhand media reporting only. We have not seen an official post-incident statement or audit report from either Bonzo Lend or Supra regarding this event. Readers citing specific figures should attach the qualifier “according to media reports.”

Editorial take: this news has little to do with the U-card in your wallet, but it’s worth reading

Let’s start with the conclusion, to avoid misreading: what was attacked here is an on-chain lending protocol — not a card issuer, and not the stablecoin itself. If your USDT sits on an exchange or in a custodial U-card account — say, Bybit Card, MPCard, or OKX Card — this incident has no direct effect on your balance. Your funds were never deposited into Bonzo Lend, and they never passed through the faulty oracle on Hedera.

The group that genuinely needs to reassess their exposure is different: people who temporarily park U-card funds in DeFi lending protocols to earn yield, planning to withdraw and top up their card when needed. This pattern was common during bull markets — deposit USDT into some protocol for 5%–10% APY, then redeem right before topping up a card. This incident is a reminder of the hidden risk in that chain: you think you’re earning interest, but you’re actually taking on the protocol’s smart-contract risk plus oracle risk — and when either of those blows up, the loss is typically principal-level, far exceeding whatever interest you’d earned.

Historical comparison: oracle manipulation is not a new script

Oracle manipulation leading a lending protocol to over-lend is a recurring attack pattern in DeFi — this is not the first instance.

The best-known public case is the Mango Markets incident from October 2022 — the attacker manipulated the oracle price feed for the MNGO token to inflate collateral value, then drained the protocol’s treasury. Losses were widely reported at around the $100 million level (figures vary by source; this reflects public reporting, not our own independent calculation).

For U-card users, both incidents send the same signal: the fund security of a yield-bearing DeFi protocol and the custodial account you use for everyday card top-ups are two entirely different trust models. Don’t lump the risks together just because both involve “USDT.”

Compliance perspective: this is not a stablecoin or card-issuer problem

One common misunderstanding needs clearing up: an oracle bug is a smart-contract-level technical flaw, unrelated to USDT’s own compliance status or to a card issuer’s licensing status. This incident will not trigger any regulatory action targeting stablecoin cards.

Readers interested in the Asia-Pacific compliance landscape can refer to our Hong Kong compliance guide and Singapore compliance guide — both jurisdictions have relatively clear licensing frameworks for stablecoins and virtual-asset service providers. Custodial U-cards operate within these frameworks, on a completely different regulatory track from an anonymous on-chain lending protocol.

The rough boundary currently looks like this:

ScenarioRegulatory status
Custodial U-cards issued by licensed institutionsClear frameworks exist in most Asia-Pacific jurisdictions
Centralized exchange cards (e.g., Bybit, OKX)Ranges from gray zone to clear licensing, depending on jurisdiction
Unaudited on-chain lending protocolsNo regulatory backstop; risk sits entirely with the user

Milestones worth watching going forward

  1. Official statements from Bonzo Lend / Supra: whether a full post-mortem and technical details of the flaw get published. None as of this writing.
  2. Whether a compensation or treasury backfill plan emerges: whether a DeFi protocol compensates users after a hack often determines whether it survives.
  3. Results of Supra’s re-audit across its other connected chains: the claim that Hedera was “missed” in this report needs official confirmation from Supra as to whether this was an isolated case.
  4. TVL changes in the Hedera ecosystem: a useful indicator of how far the fallout from this incident spreads.

Editorial recommendations

(All statements in this article involving figures and causal claims come from secondhand media reporting. We will update this page once official statements are released.)