What's Hot

    The CFTC Extended a Crypto Compliance Win to the Whole Industry

    09/20/2026

    TRON Inc.’s TRX came from HTX after UK sanctions

    09/20/2026

    MultiversX investigates potential mainnet issue

    09/20/2026
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    CoinFlashDaily | Crypto Currency News
    • Home
    • Business

      BitMart Misses Roadmap Deadline and Appoints Financial Adviser

      09/09/2026

      Circle Targets Global Payments Growth With Tazapay Acquisition

      09/09/2026

      BitGo Acquires NYDIG Institutional Trading Business

      08/28/2026

      Japan’s SBI leads $68M Fasset round at $1B valuation

      08/24/2026

      MoonPay Adds Cash App Pay for Crypto Purchases in US

      08/19/2026
    • News
      1. Business
      2. Analysis
      3. View All

      BitMart Misses Roadmap Deadline and Appoints Financial Adviser

      09/09/2026

      Circle Targets Global Payments Growth With Tazapay Acquisition

      09/09/2026

      BitGo Acquires NYDIG Institutional Trading Business

      08/28/2026

      Japan’s SBI leads $68M Fasset round at $1B valuation

      08/24/2026

      EU Cyber Resilience Act Brings 24-Hour Vulnerability Reporting Into Force

      09/20/2026

      Ethereum Institutional Supports Ethlabs’ Motion to Reduce Ethereum Block Times

      09/19/2026

      B.AI’s Global Settlement Layer for the Agent Economy

      09/19/2026

      A New Connection Between Equity Assets and Crypto Liquidity

      09/18/2026

      The CFTC Extended a Crypto Compliance Win to the Whole Industry

      09/20/2026

      MultiversX investigates potential mainnet issue

      09/20/2026

      🏴 Crypto’s New Compliance Shield?

      09/19/2026

      Crypto VC funding: Kaiko leads $180M week

      09/19/2026
    • Analysis
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      Bitcoin price tests $60k as Saylor hints at more buying

      06/07/2026

      Why Cardano’s social activity surges as ADA crashes

      06/07/2026

      AVAX price crashes to early 2021 support, is a bottom forming?

      06/06/2026

      Dogecoin price nears $0.067 risk zone after 25% monthly crash

      06/05/2026

      Ethereum Institutional Supports Ethlabs’ Motion to Reduce Ethereum Block Times

      09/19/2026

      Ethereum, Base Wallet Standards Collaboration Breaks Down

      09/15/2026

      Bitmine Stakes 5M ETH as Treasury Holdings Reach $15.8B

      09/14/2026

      Consensys Plans Split as MetaMask Becomes Standalone Company

      09/10/2026

      Digital Euro: Aspirations of a Sovereign Alternative to Crypto-Assets

      01/04/2021

      Monero Observer – Monero Tech meeting scheduled for 10 August 2026 1800 UTC

      08/03/2026

      Monero Observer – Monero v0.18.4.4 ‘Fluorine Fermi’ tagged

      07/29/2026

      Monero Observer – Monero Research Lab meeting scheduled for 19 November 2025 1700 UTC

      07/25/2026

      Monero Observer – jeffro256 submits CCS proposal for Carrot/FCMP++ dev work in Q4 2025

      07/25/2026

      EU Cyber Resilience Act Brings 24-Hour Vulnerability Reporting Into Force

      09/20/2026

      Ethereum Institutional Supports Ethlabs’ Motion to Reduce Ethereum Block Times

      09/19/2026

      B.AI’s Global Settlement Layer for the Agent Economy

      09/19/2026

      A New Connection Between Equity Assets and Crypto Liquidity

      09/18/2026
    • Markets
    • Events
    Button
    CoinFlashDaily | Crypto Currency News
    Home»News»Bitcoin News»Lien Finance hit by $542K exploit tied to bond token logic bug
    Bitcoin News

    Lien Finance hit by $542K exploit tied to bond token logic bug

    adminBy admin07/24/2026没有评论6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Lien Finance has lost about $542,000 in USDC after an attacker exploited a flaw in its bond token logic to mint unsupported assets and drain liquidity from the protocol.

    Summary

    • Lien Finance lost about $542,000 in USDC after attackers exploited a flaw in its bond token exchange logic.
    • Security researchers said the exploit allowed unsupported bond tokens to be minted and exchanged for real liquidity from the protocol.
    • The incident adds to a series of DeFi exploits this month as researchers continue to examine weaknesses in protocol pricing and validation logic.

    Blockchain security firm SlowMist said the exploit targeted Lien Finance’s bond exchange mechanism, allowing the attacker to create bond tokens without destroying the corresponding input bonds before swapping them for USDC. The firm estimated the loss at roughly 542,144.63 USDC and identified the attacker wallet as 0x0d7d…1808a.

    ?SlowMist TI Alert?

    ? @LienFinance Loss: ~542k USD

    ? Root Cause: The `exchangeEquivalentBonds` function in BondMakerCollateralizedEth lacks proper multiset integrity checks. It only counts total exception occurrences instead of verifying each bondID’s appearance per group.…

    — SlowMist (@SlowMist_Team) July 24, 2026

    According to SlowMist, the vulnerability was located in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract. Its analysis said the function failed to properly verify the integrity of bond groups during exchanges. Instead of checking whether every bond ID appeared the required number of times, the contract counted only the total number of exception entries. By repeatedly using the same exception bond ID in the output group, the attacker satisfied the validation logic while omitting another required bond from the input.

    SlowMist said the flaw allowed the attacker to mint new BondTokens that appeared valid even though no matching collateral had been consumed. The newly created assets were then exchanged for USDC through three pre-authorized endpoints, resulting in the withdrawal of about 542,144.63 USDC from the victim address 0xa961684a3a654fb2cca8f8991226c0cefc514d80.

    The security firm identified the affected contracts as 0xda6fc5625e617bb92f5359921d43321cebc6bef0 and 0x843225cf6e663e4454732d6b551a737ac7b47de0.

    Permissionless bond registration and pricing logic under scrutiny

    Separate on-chain analysis from DefimonAlerts, later amplified by researcher exvulsec, described the incident as a protocol logic failure that combined permissionless bond registration with pricing weaknesses inside Lien Finance’s over-the-counter bond pools.

    ? @LienFinance – Loss $542K (2026-07-24)

    Network: Ethereum

    Type: Oracle / Price Manipulation

    Lien Finance’s GeneralizedDotc bond-to-ERC20 OTC pools were drained. An attacker-deployed orchestration contract (0xe74d17c1) permissionlessly registered new bond groups on the…

    — Defimon Alerts (@DefimonAlerts) July 24, 2026

    According to that analysis, the attacker first deployed an orchestration contract before registering a new bond group through the BondMakerCollateralizedEth contract. Because the registration process did not require governance approval, the attacker was reportedly able to introduce a bond group built around a malicious payoff function.

    The report said the crafted bond tokens were then routed into Lien Finance’s GeneralizedDotc OTC pools. It pointed to the protocol’s internal _calcRateBondToErc20 function, saying it appears to have assigned excessive value to the newly created bonds despite their lack of genuine collateral backing.

    As a result, the attacker exchanged what researchers described as effectively unsupported structured products for real USDC liquidity held in the protocol’s pools. The primary affected liquidity pool was the GeneralizedDotc contract at 0x656e…9ef18, while the attacker wallet received the proceeds through the main exploit transaction.

    Researchers examining the exploit have described it as a protocol pricing and validation failure rather than a conventional smart contract exploit such as reentrancy or an access control bypass. According to the published analysis, the attack relied on introducing synthetic financial instruments whose economic value was not sufficiently validated before they became eligible for OTC swaps.

    The researchers compared the incident with April’s Drift Protocol exploit, where attackers reportedly introduced fabricated collateral that the protocol accepted at inflated values before real assets were withdrawn. They noted that the two cases differ in implementation but share a similar pattern of exploiting valuation logic instead of breaking cryptographic protections.

    Latest incident adds to a string of DeFi exploits

    The Lien Finance exploit comes during an active period for decentralized finance security incidents.

    Just one day earlier, on-chain analytics platform Lookonchain described July 23 as “Hackers’ Day” after three separate exploits resulted in combined reported losses of about $35.55 million. Those incidents included a $24.15 million exploit involving AFX Trade’s bridge infrastructure, a $7.54 million attack on the Verus Ethereum Bridge, and a separate $3.86 million exploit affecting B² Network.

    In the AFX incident, blockchain security firm Blockaid said attackers drained about $24.15 million in USDC from infrastructure operated by the protocol rather than Arbitrum’s native bridge. Offchain Labs separately confirmed that Arbitrum’s core bridge was not compromised and said the incident involved third-party infrastructure.

    Meanwhile, Blockaid also linked the latest Verus Ethereum Bridge exploit to the same bridge contract, entry path and apparent bug class involved in the project’s May breach. The firm said the July attack generated unbacked Ethereum-side payouts through the bridge’s import process, although a complete technical explanation had not yet been published.

    Earlier this month, Lazy Summer Protocol lost about $6.04 million in a share price manipulation attack, while Bonzo Finance on Hedera reported losses of around $9 million following an oracle-related exploit. Allbridge Core also suffered a flash-loan-driven stable pool attack that drained roughly $1.65 million, and Polychain-backed Cascade lost approximately $1.34 million in another exploit during July.

    ?Blockaid’s exploit detection system has identified an ongoing exploit on @summerfinance_.
    ~$6M drained so far.
    More details in ?

    — Blockaid (@blockaid_) July 6, 2026

    Researchers tracking decentralized finance attacks have estimated cumulative losses exceeding $630 million during the first seven months of 2026. Their data identifies oracle manipulation, pricing flaws, compromised credentials and bridge validation weaknesses among the most common attack vectors recorded this year.

    BondMaker architecture has faced security issues before

    For long-time Ethereum developers, the latest exploit revisits an architecture that has drawn security attention before.

    In September 2020, a white-hat group led by security researcher Samczsun prevented the loss of roughly $10 million after identifying a flaw in Lien Finance’s original BondMaker system.

    Security researchers at the time said the earlier vulnerability allowed attackers to create empty bond groups that could be exchanged for properly collateralized ones through an equivalence function, making it possible to extract Ether without matching backing. The issue was intercepted before malicious actors could exploit it, and the recovery became one of Ethereum’s most prominent coordinated white-hat rescue efforts.

    Unlike the 2020 incident, the latest exploit resulted in an actual loss after attackers used weaknesses in bond validation and pricing logic to withdraw USDC from live liquidity pools. At the time of publication, Lien Finance had not released a detailed technical postmortem or announced whether any of the stolen funds had been frozen or recovered.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    MultiversX investigates potential mainnet issue

    09/20/2026

    Crypto VC funding: Kaiko leads $180M week

    09/19/2026

    Hong Kong plans 24/7 CBDC settlement for tokenized deposits by year end

    09/18/2026

    RWA futures volume jumps 142-fold after crypto’s $19B wipeout

    09/17/2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    01/20/2021

    Jack Dorsey Says Bitcoin Will Unite The World

    01/15/2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    01/15/2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    The CFTC Extended a Crypto Compliance Win to the Whole Industry

    09/20/2026

    TRON Inc.’s TRX came from HTX after UK sanctions

    09/20/2026

    MultiversX investigates potential mainnet issue

    09/20/2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook Twitter Instagram Pinterest
    • Home
    • Business
    • Markets
    • News
    • Contact us
    © {2025-2026} Coinflashdaily.com.

    Type above and press Enter to search. Press Esc to cancel.