According to Tokenpost, citing a Protos report, the lending protocol Bonzo Lend on the Hedera (HBAR) network was attacked over the weekend, with losses reported at around $9 million. Per the report, the attacker exploited a flaw in an oracle price feed to artificially inflate collateral value, then borrowed far more than the collateral was actually worth. The report further states that the issue traces back to an oracle provided by infrastructure vendor Supra Network — Supra had reportedly patched oracles across several chains recently, but the Hedera contract was allegedly missed, ultimately becoming the target.
To be clear: the dollar figure and the “patched multiple chains but missed Hedera” causal claim currently come from secondhand media reporting only. We have not seen an official post-incident statement or audit report from either Bonzo Lend or Supra regarding this event. Readers citing specific figures should attach the qualifier “according to media reports.”
Editorial take: this news has little to do with the U-card in your wallet, but it’s worth reading
Let’s start with the conclusion, to avoid misreading: what was attacked here is an on-chain lending protocol — not a card issuer, and not the stablecoin itself. If your USDT sits on an exchange or in a custodial U-card account — say, Bybit Card, MPCard, or OKX Card — this incident has no direct effect on your balance. Your funds were never deposited into Bonzo Lend, and they never passed through the faulty oracle on Hedera.
The group that genuinely needs to reassess their exposure is different: people who temporarily park U-card funds in DeFi lending protocols to earn yield, planning to withdraw and top up their card when needed. This pattern was common during bull markets — deposit USDT into some protocol for 5%–10% APY, then redeem right before topping up a card. This incident is a reminder of the hidden risk in that chain: you think you’re earning interest, but you’re actually taking on the protocol’s smart-contract risk plus oracle risk — and when either of those blows up, the loss is typically principal-level, far exceeding whatever interest you’d earned.
- Within 7 days: if you currently have card top-up funds parked in a small or newly launched lending protocol, check which oracle it relies on and whether it has completed an audit; redeem first if in doubt.
- Within 30 days: watch whether Supra Network issues an official statement or compensation plan for this incident. As of now, the Supra official site only carries product descriptions, with no announcement about this event.
- Within 90 days: incidents like this typically push oracle providers to run full cross-chain re-audits. DeFi activity on the Hedera ecosystem may take a short-term hit, but this won’t spread to centralized card-issuing channels.
Historical comparison: oracle manipulation is not a new script
Oracle manipulation leading a lending protocol to over-lend is a recurring attack pattern in DeFi — this is not the first instance.
The best-known public case is the Mango Markets incident from October 2022 — the attacker manipulated the oracle price feed for the MNGO token to inflate collateral value, then drained the protocol’s treasury. Losses were widely reported at around the $100 million level (figures vary by source; this reflects public reporting, not our own independent calculation).
- Similarities: the core attack logic is the same — collateral is artificially overvalued, and the attacker borrows far more than its real value.
- Differences: in the Mango case, the manipulated asset was the spot price of a low-liquidity token; this incident is reportedly a contract-level flaw at the oracle provider itself (a patch missed on one chain) — closer to an infrastructure defect than market manipulation.
For U-card users, both incidents send the same signal: the fund security of a yield-bearing DeFi protocol and the custodial account you use for everyday card top-ups are two entirely different trust models. Don’t lump the risks together just because both involve “USDT.”
Compliance perspective: this is not a stablecoin or card-issuer problem
One common misunderstanding needs clearing up: an oracle bug is a smart-contract-level technical flaw, unrelated to USDT’s own compliance status or to a card issuer’s licensing status. This incident will not trigger any regulatory action targeting stablecoin cards.
Readers interested in the Asia-Pacific compliance landscape can refer to our Hong Kong compliance guide and Singapore compliance guide — both jurisdictions have relatively clear licensing frameworks for stablecoins and virtual-asset service providers. Custodial U-cards operate within these frameworks, on a completely different regulatory track from an anonymous on-chain lending protocol.
The rough boundary currently looks like this:
| Scenario | Regulatory status |
|---|---|
| Custodial U-cards issued by licensed institutions | Clear frameworks exist in most Asia-Pacific jurisdictions |
| Centralized exchange cards (e.g., Bybit, OKX) | Ranges from gray zone to clear licensing, depending on jurisdiction |
| Unaudited on-chain lending protocols | No regulatory backstop; risk sits entirely with the user |
Milestones worth watching going forward
- Official statements from Bonzo Lend / Supra: whether a full post-mortem and technical details of the flaw get published. None as of this writing.
- Whether a compensation or treasury backfill plan emerges: whether a DeFi protocol compensates users after a hack often determines whether it survives.
- Results of Supra’s re-audit across its other connected chains: the claim that Hedera was “missed” in this report needs official confirmation from Supra as to whether this was an isolated case.
- TVL changes in the Hedera ecosystem: a useful indicator of how far the fallout from this incident spreads.
Editorial recommendations
- Users holding custodial U-cards (Bybit, MPCard, OKX, etc.): no action needed. Your balance has nothing to do with this incident.
- Users parking card top-up funds in DeFi protocols for yield: check the oracle and audit status of the protocol you’re using, stay cautious with newly launched protocols with small TVL, and keep top-up funds in a custodial account or redeem as needed — don’t take on principal-level risk for a few percentage points of APY.
- Users planning to use U-cards long-term in Asia-Pacific: prioritize licensed, custodial paths. See our Bybit Card review and MPCard review, and evaluate “whether it works for spending” separately from “where your funds are safer.”
- What not to do: don’t panic-sell USDT or HBAR over this news — the impact is confined to a single lending protocol and has no direct connection to stablecoin solvency or card-issuing channels.
(All statements in this article involving figures and causal claims come from secondhand media reporting. We will update this page once official statements are released.)