📅 Sunday, 13 September 2026 · --:-- UTC Follow us
Ecosystem
ID EN
Lien Finance Dibobol 542 Ribu USDC - Modusnya Cuma Mengulang ID Obligasi Bodong Tanpa Agunan

Lien Finance Exploited for $542K USDC by Replaying Fake Uncollateralized Bond IDs

Lien Finance has lost 542,144.63 USDC following a logic exploit involving its bond tokens. The attack, detected and reported by security firm SlowMist, adds to the growing tally of DeFi ecosystem losses, which are now estimated to have surpassed $630 million across the first seven months of 2026.

The incident did not involve advanced cryptographic techniques. Instead, hackers exploited a logic flaw in smart contracts to mint unbacked assets and swap them for real funds.

Validation Flaw in Minting Contract

The root cause of the exploit lies within the exchangeEquivalentBonds function in the BondMakerCollateralizedEth contract. While playing a key role in asset minting, the function failed to properly verify the integrity of bond groups. Rather than checking whether each required bond ID appeared individually, the contract merely counted the total number of excluded entries.

That counting weakness allowed the attacker to manipulate the system. By repeating the same bond ID multiple times, they were able to mint new BondToken tokens. These tokens appeared valid to the contract, despite having no real collateral backing their value.

The fake tokens were immediately swapped for USDC via three pre-authorized endpoints, draining funds from victim address 0xa961…4d80. On-chain analysis indicates the attacker’s wallet 0x0d7d…808a served as the recipient for funds drained from two primary affected contracts: 0xda6f…ef0 and 0x8432…de0.

Offloading Fake Bonds to the OTC Pool

A joint report from DefimonAlerts and researcher exvulsec uncovered the second stage of the attack. The exploit combined unauthorized bond registration bypassing governance approval with a pricing flaw in Lien Finance’s OTC pool.

The attacker deployed an orchestration contract to register bond groups with malicious payment functions without governance approval. The fake tokens were then routed to the primary liquidity pool, GeneralizedDotc, located at address 0x656e…ef18.

Within this pool, the internal function _calcRateBondToErc20 overvalued the newly deposited bonds. This enabled the hacker to sell the uncollateralized assets and extract legitimate USDC.

DeFi Valuation Flaw Patterns

Security researchers drew parallels between this exploit and the attack on Drift Protocol in April 2026. Both incidents took advantage of asset pricing logic flaws rather than cryptographic vulnerabilities such as access control bypasses or reentrancy attacks.

Lien Finance itself has a long history with similar vulnerabilities. In September 2020, white hat hackers led by Samczsun prevented a $10 million loss in Lien Finance’s original BondMaker contract. The issue discovered back then was similar, though funds were successfully rescued at the time.

As of writing, Lien Finance has not released a technical postmortem to the community or announced any fund-freezing measures. Logic errors in evaluating asset values continue to prove among the most lucrative attack vectors for DeFi hackers.

Reported via crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
📩 KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share