Need help? Support
BITCOIN
Tether Dominance USDT.D

Cross-chain exploit drains $5.25M to ETH

Published Updated 693 words 4 min read

TLDR

A Hedera-based DeFi lending protocol was exploited, with about $5.25 million in stolen assets bridged to Ethereum in a cross-chain attack.

  1. A flaw in a third-party price oracle let the attacker over-borrow on Bonzo Lend, then move roughly $5.25 million to Ethereum and convert it into ETH and WBTC.
  2. Total borrowed assets were around $9 million, Hederas DeFi TVL fell sharply, and HBAR dipped, but current evidence points to protocol-level and oracle risk, not a core Hedera failure.
  3. The funds sit in a watched Ethereum wallet; the main variables now are remediation by Hedera and Supra, any recovery, and whether the attacker launders the ETH and WBTC through mixers.

Confidence: moderate because multiple security firms and outlets agree on the mechanics and amounts, while Hederas official investigation is still ongoing.

Deep Dive

1. How The Exploit Drained Funds To Ethereum

Blockchain security firm PeckShield reports that about $5.25 million was stolen from the Hedera ecosystem and then bridged to Ethereum, where the attackers wallet holds 2,360 ETH and 15.58 WBTC, funded initially with 1 ETH from Tornado Cash as gas and obfuscation capital. This cross-chain movement of stolen assets is at the core of the drains $5.25M to ETH headline.

More detailed incident reports attribute the root cause to Bonzo Lend, a Hedera-based lending protocol that relied on a Supra oracle verifier. By depositing a small amount of SAUCE tokens and manipulating the oracles price update, the attacker made their collateral appear extremely valuable, enabling them to borrow millions in USDC and wrapped HBAR before bridging and swapping into ETH and WBTC via LayerZero and related infrastructure on Ethereum, as described by TradingView and CoinDesk coverage of Bonzo and Sauce Protocol exploits.PeckShield alert on Hedera exploit

2. Damage To Bonzo, Hedera DeFi, And HBAR

Bonzos own preliminary report and independent analyses put the total borrowed amount near $9.05 million, with roughly $10.06 million in principal briefly outstanding before a white-hat wallet pledged to return around $1 million. That places the $5.25 million already bridged to Ethereum as a substantial subset of the overall protocol loss.Coindesk report on Bonzo exploit

The impact on Hederas DeFi ecosystem has been meaningful: Hederas total value locked reportedly fell about 40 percent in 24 hours to roughly $25.7 million, while Bonzos TVL dropped around 77 percent. HBAR itself traded lower, around the 35 percent range, but within an already bearish trend channel, suggesting sentiment damage more than a catastrophic market shock.Tokenpost summary of TVL drop Hedera has publicly indicated the issue is isolated to the oracle verifier rather than its core network, which, if confirmed, frames this as a DeFi application and infrastructure problem rather than a base-layer compromise.

3. Cross-Chain And Oracle Risk, Plus What To Watch

This exploit fits a broader pattern in 2026, where oracle failures and cross-chain bridges have been recurring weak points in DeFi. Security trackers note hundreds of millions of dollars lost to similar cross-chain and oracle-related incidents this year, underlining that middleware (bridges, oracles, verifiers) can be as system-critical as the chains themselves.PeckShields broader bridge exploit discussion

Key things to watch now are:

  1. Formal postmortems and fixes from Supra, Bonzo, and Hedera, which will determine whether confidence in Hedera DeFi can stabilize.
  2. Any successful recovery or negotiations with the white-hat wallet and, potentially, the main attacker wallet holding the ETH and WBTC.
  3. On-chain movement of the 2,360 ETH and 15.58 WBTC, particularly if they begin to cycle through Tornado Cash or other privacy tools, which would reduce chances of recovery and may attract additional regulatory scrutiny.
What this means

For users, the main risk lies in DeFi protocol and oracle design rather than HBAR itself, so due diligence should focus on how lending platforms and bridges validate prices and secure cross-chain flows.

Conclusion

The $5.25 million drained to Ethereum reflects a classic DeFi failure: a manipulated oracle on a lending protocol allowed excessive borrowing, then cross-chain bridges turned Hedera-based assets into ETH and WBTC. The incident has stressed Hederas DeFi TVL and damaged confidence, but current evidence points to a verifier and application flaw rather than a core Hedera network breach. What will matter for crypto users is how quickly the teams patch the oracle layer, whether any funds are clawed back, and whether this prompts stronger standards for cross-chain and oracle security across the broader ecosystem.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top