en

Lien Finance Suffers $542,000 Attack

image
rubric logo Security
like fud hodl 11

Lien Finance lost approximately 542,000 $USDC due to a vulnerability in the bond token exchange logic. The attacker exploited this flaw to create unbacked assets and drain the protocol’s liquidity. Security researchers stated that this vulnerability allowed new tokens to be minted and exchanged for real liquidity without destroying the bond tokens.

Technical Details of the Attack

Blockchain security firm SlowMist announced that the attack targeted Lien Finance’s bond exchange mechanism. The attacker used the exchangeEquivalentBonds function in the BondMakerCollateralizedEth contract to create bond tokens without destroying the input bonds and then exchanged them for $USDC. This resulted in the withdrawal of approximately 542,144.63 $USDC. SlowMist stated that the attack occurred because the bond groups were not sufficiently verified during the exchange. The wallet address used by the attacker was identified as 0x0d7d…1808a.

Protocol Weaknesses and Their Consequences

On-chain analysis by DefimonAlerts revealed the attack occurred due to permissionless bond registration and pricing vulnerabilities. The attacker created bonds containing a malicious payment function by registering a new batch of bonds through the BondMakerCollateralizedEth contract. These bonds were routed to Lien Finance’s OTC pools and replaced with actual $USDC liquidity. Following the attack, several contracts were affected, including Lien Finance’s GeneralizedDotc contract.

This incident adds another vulnerability to the recently increasing number of security breaches in DeFi protocols. In July, other protocols also suffered similar attacks, resulting in losses totaling millions of dollars. Lien Finance has not yet released a detailed technical report following this attack. Researchers note that such attacks stem from weaknesses in the protocol’s pricing and validation logic.