Lien Finance Loses $542,000 in Bond Token Exchange Exploit

USDC0.02%
Key Takeaways
  • Lien Finance lost approximately 542,000 USDC due to a vulnerability in its BondMakerCollateralizedEth contract during July.
  • The attacker exploited the exchangeEquivalentBonds function to create unbacked bond tokens and exchanged them for 542,144.63 USDC without verification.
  • Security researchers from SlowMist and DefimonAlerts identified the flaw as stemming from permissionless bond registration and insufficient pricing validation logic.

Lien Finance lost approximately 542,000 USDC due to a vulnerability in its bond token exchange logic. The attacker exploited a flaw in the protocol's BondMakerCollateralizedEth contract that allowed the creation of unbacked assets and subsequent drainage of liquidity. Security researchers from SlowMist stated that the vulnerability enabled new tokens to be minted and exchanged for real liquidity without destroying the corresponding bond tokens. This incident occurred during July, a period marked by multiple security breaches across DeFi protocols resulting in millions of dollars in total losses.

Attacker Exploits exchangeEquivalentBonds Function in Bond Contract

Blockchain security firm SlowMist announced that the attack targeted Lien Finance's bond exchange mechanism. The attacker used the exchangeEquivalentBonds function in the BondMakerCollateralizedEth contract to create bond tokens without destroying the input bonds and then exchanged them for USDC. This resulted in the withdrawal of approximately 542,144.63 USDC. SlowMist stated that the attack occurred because the bond groups were not sufficiently verified during the exchange. The wallet address used by the attacker was identified as 0x0d7d…1808a.

SlowMist and DefimonAlerts Identify Vulnerability in Bond Registration System

On-chain analysis by DefimonAlerts revealed the attack occurred due to permissionless bond registration and pricing vulnerabilities. The attacker created bonds containing a malicious payment function by registering a new batch of bonds through the BondMakerCollateralizedEth contract. These bonds were routed to Lien Finance's OTC pools and replaced with actual USDC liquidity. Following the attack, several contracts were affected, including Lien Finance's GeneralizedDotc contract. Lien Finance has not yet released a detailed technical report following this attack. Researchers note that such attacks stem from weaknesses in the protocol's pricing and validation logic.

FAQ

How did the attacker exploit Lien Finance's bond system? The attacker used the exchangeEquivalentBonds function in the BondMakerCollateralizedEth contract to create bond tokens without destroying the input bonds, then exchanged them for USDC. This was possible because bond groups were not sufficiently verified during the exchange process.

What contracts were affected by the Lien Finance attack? Several contracts were affected following the attack, including Lien Finance's GeneralizedDotc contract. The attacker registered malicious bonds through the BondMakerCollateralizedEth contract and routed them to Lien Finance's OTC pools.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments