Lien Finance loses 542,000 dollars due to clever attack on contract
The DeFi protocol Lien Finance has fallen victim to an attack in which approximately $542.000 in USDC was stolen. Security firm SlowMist identified the vulnerability in the system and revealed how attackers systematically managed to exploit the protocol.
Lien Finance is available at OKX and Bybit.
The flaw in the contract
The root cause of the leak is hidden in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract. This component of the system checks whether all bond exceptions are correctly handled, but does so in an insufficient manner. The contract only counts the total number of exceptions, instead of verifying each individual bondID per group.
This trigger point made it possible for attackers to include the same exception bondID multiple times in the output group. By executing this trick, they could artificially manipulate the exception count and thus mask a missing input exception.
The exploit in action
The attackers exploited this logic to create new BondTokens without depositing the corresponding input bonds. This meant they could generate tokens out of thin air. They then exchanged these artificial tokens for USDC by using three pre-authorised endpoints in the system.
The thief used wallet address 0x0d7d9023531ad1a88414e216ee2715f63561808a to drain a total of 542,144.628604 USDC from the victim address 0xa961684a3a654fb2cca8f8991226c0cefc514d80. This fits into a series of previously reported security incidents in the DeFi space, similar to other protocol breaches.
Consequences and reactions
The vulnerable contracts were located at addresses 0xda6fc5625e617bb92f5359921d43321cebc6bef0 and 0x843225cf6e663e4454732d6b551a737ac7b47de0. SlowMist notified the Lien Finance team and published technical details to help other projects detect similar flaws in their own code.
This incident underscores how critical thorough security checks are for DeFi platforms. Even subtle flaws in verification logic can have serious consequences if attackers manage to find them. The advice for users of such protocols remains unchanged: before committing large sums to new or unknown contracts, an audit by recognised security firms should have taken place.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.