Hedera’s Bonzo and DxSale Hit by Separate DeFi Exploits as Security Concerns Mount

Two more DeFi security incidents have shaken the crypto sector, with the Hedera-based lending protocol Bonzo losing about $9 million in an oracle exploit and DxSale suffering a separate $7.3 million drain on BNB Chain. The back-to-back incidents highlight how quickly flaws in DeFi systems can turn into major losses for users and protocols alike.

 

Bonzo Finance said the Hedera attack was caused by a third-party oracle verification flaw, not by a problem in Hedera’s core network or Bonzo’s own smart contracts. Attackers reportedly deposited just 250 SAUCE tokens, then used a manipulated price update to inflate the token’s value by roughly 12 orders of magnitude before borrowing 6.63 million USDC and 34.5 million wrapped HBAR from the lending pool. In simple terms, the attacker made weak collateral look extremely valuable, then used that fake value to drain funds.

 

DxSale’s loss came from a different kind of weakness. Reports say the exploit affected old liquidity locker contracts on BNB Chain and drained about $7.3 million from more than 1,400 liquidity providers. Investigators linked the attack to privileged contract functions and a hidden backdoor, which allowed funds that were supposed to remain locked to be withdrawn. Some of the stolen assets were traced through wallets and deposit addresses associated with Binance.

 

These incidents matter because they show that DeFi risks do not always come from one broken line of code. In Bonzo’s case, the weak point was an oracle, which is the outside data source that tells a protocol what an asset is worth. In DxSale’s case, the danger came from contract design and access control in older infrastructure. Both examples show that even established projects can be exposed if key systems are not tightly verified and regularly reviewed.

 

For users, the message is straightforward: high yields and fast growth in DeFi often come with hidden technical risk. For developers and investors, these attacks are another reminder that audits, oracle checks, and access controls are not optional extras—they are core defenses. As DeFi continues to expand, the pressure on protocols to prove their security is only getting stronger.

 

 

 

 

Disclaimers: All contents in this article are for informational purposes only and does not constitute any form of advice.Third-party websites and their content are provided for informational purposes and user convenience only. Rola News does not control, endorse, or assume responsibility for any Third-party websites, including their content, accuracy, privacy practices, or any subsequent changes or updates made to them. This article is AI-assisted and has been reviewed by our editorial team.