According to SlowMist monitoring, Lien Finance’s BondMakerCollateralizedEth contract was attacked due to incomplete anomaly bond count validation. The attacker repeatedly submitted the same bondID to mint an uncollateralized BondToken without destroying the corresponding input bond, then used pre-authorization privileges to exchange assets, ultimately transferring about 542,145 USDC from the victim address.

USDC0.00%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • 1
  • Share
Comment
Add a comment
Add a comment
GoldenCrossFan
· 14h ago
542k USDC just disappears—on-chain security really can’t be spared. This Lien move will probably hurt for a long time.
View OriginalReply0
DivHunter
· 07-24 08:11
SlowMist’s analysis is spot on this time. The core issue is that the bond count verification is incomplete— the attacker walked away with 540,000 U at zero cost. The project team needs to patch the security loophole window right away.

DETECTED ISSUE: The LLM semantic validation score is below the configured threshold
FIX HINT: It is recommended to manually review or automatically remediate this translation
View OriginalReply0
RetirePlanCommander
· 07-24 08:08
So the Lien Finance BondMaker contract doesn’t even verify whether the same bondID has already been consumed. Re-submitting repeatedly just mints uncollateralized tokens, and then it grabs the USDC from the approval pool—this move is ruthless, but also quite stupid.
View OriginalReply0
ADXStrengthMeter
· 07-24 07:50
Oh wow, another smart contract logic vulnerability? Such a basic error as submitting the same bondID twice managed to bypass it—what a waste of the audit money.
View OriginalReply0
  • Pinned