T
iTokenly

Bondly Finance hack — July 2021

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 15, 2021
Target typeToken contract
Loss$7,500,000Published estimates range $5,900,000 to $7,500,000Price at time of incident
MethodPrivate key compromisePer the project's own post-mortem, the attacker gained access to a password-manager account belonging to Bondly's chief executive that stored the recovery mnemonic for his hardware wallet, giving control of the BONDLY token contract and corporate wallets. 373,088,023 BONDLY were moved out of the Ethereum staking rewards contract, plus 271,790,246 on BNB Chain and 6,620,128 on Polygon. 200,460,000 were deposited into MANTRA DAO's Zenterest market to mint zenBONDLY and borrow against it; the remainder was sold into liquidity pools.
ChainsEthereum, BNB Chain, Polygon
OutcomeProject relaunched

What happened

Bondly Finance, a token and NFT project later renamed Forj, was drained on 15 July 2021 after its administrative keys were compromised.

According to the project's own post-mortem, the attacker obtained access to a password account belonging to chief executive Brandon Smith that contained the recovery mnemonic for his hardware wallet, giving control of the BONDLY token contract and corporate wallets. At 00:16:01 UTC on 15 July, 373,088,023 BONDLY left the BondlyTokenStakingRewards contract on Ethereum; a further 271,790,246 BONDLY on BNB Chain and 6,620,128 BONDLY on Polygon were also taken. Halborn characterised the Ethereum volume as newly minted, writing that the attacker was able to mint 373 million BONDLY using the owner transfer operation.

A minute later the attacker moved 200,460,000 BONDLY into MANTRA DAO's Zenterest lending market, minting 20,036,019 zenBONDLY, and between 00:19:11 and 00:26:43 UTC borrowed against it until the liquidity of most major Zenterest assets was reduced to zero. The remaining tokens were sold into liquidity pools. BONDLY fell about 82% within seven hours, from roughly $0.06 to $0.01. Note that the two post-mortems conflict on units: Bondly's own account reads as 200,460,000 zenBONDLY minted, while MANTRA's records 20,036,019.58587687 zenBONDLY, which is consistent with a roughly 10:1 deposit ratio.

Loss estimates differ and none comes from Bondly itself, which published no USD total. Crypto Briefing reported gains of about $7.5 million, of which roughly $1.45 million was still sitting in one Ethereum address at the time of writing. A lower figure of about $5.9 million also circulates in secondary coverage.

Whether this was an intrusion or an insider act was disputed. PeckShield's assessment was that it was 'potentially a rug pull as the owner pulls the trigger in transferring out 373M $BONDLY to sell'; others argued a key compromise was more plausible, and Halborn noted the attack did not exploit any vulnerability in the protocol's smart contract. No charges have been brought. Bondly redeployed a multisig-controlled token contract and issued replacement tokens to holders based on pre-hack snapshots, and MANTRA DAO committed that 'ZERO OM tokens will be sold' to cover Zenterest's resulting bad debt.

Sources

  1. Bondly / ForjPrimary · retrieved 2026-08-01
  2. MANTRA DAOPrimary · retrieved 2026-08-01
  3. Crypto BriefingSecondary · retrieved 2026-08-01
  4. CoinJournalSecondary · retrieved 2026-08-01
  5. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://forj.medium.com/bondly-attack-july-14th-2021-postmortem-beb7cf02e9ba

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Bondly Finance hack — July 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bondly-finance
https://itokenly.com/hacks/bondly-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.