Lien Finance hit by $542K exploit linked to bond token logic bug

Lien Finance lost nearly $542,000 in USDC after an attacker exploited a flaw in the bond token’s logic to pool unbacked assets and de-liquidate the deal.
Summary
- Lien Finance lost approximately $542,000 in USDC after attackers exploited a flaw in the logic behind the bond token exchange.
- Security researchers said the exploit allowed unbacked bond tokens to be created and exchanged for real money from regulation.
- This incident adds to the series of DeFi actions this month as researchers continue to examine the weakness of the protocol’s pricing and authentication logic.
Blockchain security firm SlowMist said the exploit targets Lien Finance’s bond exchange mechanism, which allows an attacker to create bond tokens without destroying the corresponding input bonds before exchanging them for USDC. The company estimated the loss at around 542,144.63 USDC and identified the attacker’s wallet as 0x0d7d…1808a.
According to SlowMist, the vulnerability was discovered in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract. Its analysis said the service failed to properly ensure the integrity of the bond groups during the transaction. Instead of checking if every bond ID appears the required number of times, the contract only counts the total number of unique entries. By repeatedly using the same ID of a different bond in the output group, the attacker satisfies the authentication logic while extracting another required bond from the input.
SlowMist said the flaw allowed an attacker to create new BondTokens that appear to be valid even though no identical collateral is used. The newly created assets were then exchanged for USDC through three pre-authorized points, resulting in the withdrawal of 542,144.63 USDC to the victim’s address 0xa961684a3a654fb2cca8f8991226c0cefc514d80.
The security firm identified the affected contracts as 0xda6fc5625e617bb92f5359921d43321cebc6bef0 and 0x843225cf6e663e4454732d6b551a737ac7b47de0.
Unauthorized bond registration and pricing considerations are under review
A separate analysis of the thread from DefimonAlerts, later raised by researcher exvulsec, described the incident as a protocol logic failure involving unauthorized bond registration and price weakness within Lien Finance’s bond pools.
According to that analysis, the attacker first used the orchestration contract before registering a new group of bonds with the BondMakerCollateralizedEth contract. Because the registration process did not require administrative permission, the attacker was reportedly able to launch a group of bonds designed for malicious payment activity.
The report said the created bond tokens were then transferred to Lien Finance’s GeneralizedDotc OTC pools. It pointed to the protocol’s internal _calcRateBondToErc20 function, saying it seemed to assign an overestimate to newly created bonds despite their lack of real support.
As a result, the attacker exchanged what the researchers described as products that are not effectively backed by real USDC currency stored in the protocol’s pools. The main pool of money affected was the GeneralizedDotc contract at 0x656e…9ef18, while the wallet attacker received the proceeds of the massive exploit.
Researchers examining the exploit described it as a protocol price and authentication failure instead of a common smart contract exploit such as re-entry or bypassing an access control. According to the published analysis, the attack relies on introducing financial instruments whose economic value is not sufficiently guaranteed before they are eligible for OTC exchange.
Researchers compared the incident to April’s Drift Protocol exploit, where attackers reportedly presented a fake guarantee that the protocol was accepted with inflated values before real assets were withdrawn. They noted that these two scenarios differ in implementation but share the same pattern of using logic to measure rather than break cryptographic security.
The latest incident adds to the series of DeFi actions
Lien Finance takes advantage of the time-effectiveness of distributed financial security events.
Just one day earlier, on-chain analytics platform Lookonchain described July 23 as “Hacker Day” after three separate exploits resulted in a combined reported loss of approximately $35.55 million. Those incidents include a $24.15 million exploit involving the AFX Trade bridge infrastructure, a $7.54 million attack on the Verus Ethereum Bridge, and a separate $3.86 million exploit affecting the B² Network.
In the AFX incident, blockchain security firm Blockaid said the attackers spent an estimated $24.15 million in USDC and infrastructure used by the project instead of the traditional Arbitrum bridge. Offchain Labs separately confirmed that Arbitrum’s main bridge was not compromised and said the incident involved third-party infrastructure.
Meanwhile, Blockaid has also linked the latest Verus Ethereum Bridge exploit to the same bridge contract, entry method and apparent bug category involved in the May project breach. The company said the July attack generated unsupported Ethereum-side payments through a bridge import process, although a full technical explanation had not been published.
Earlier this month, Lazy Summer Protocol lost about $6.04 million in a share price attack, while Bonzo Finance on Hedera reported a loss of about $9 million following an oracle-related exploit. Allbridge Core also suffered a flash-loan-driven stable pool attack that took out about $1.65 million, while Polychain-backed Cascade lost about $1.34 million in another exploit in July.
Researchers tracking attacks on decentralized finance have estimated cumulative losses exceeding $630 million during the first seven months of 2026. Their data points to oracle spoofing, pricing errors, compromised credentials and bridge authentication weaknesses among the most common attacks recorded this year.
The BondMaker Architecture has faced security issues before
For long-time Ethereum developers, the latest exploit revisits structures that have drawn security attention before.
In September 2020, a white hat team led by security researcher Samczsun prevented a loss of nearly $10 million after identifying a bug in BondMaker’s first Lien Finance program.
Security researchers at the time said that the previous vulnerability allowed attackers to create empty groups of bonds that could be modified to be properly combined using the balancing function, making it easy to extract Ether without mutual support. The issue was caught before malicious actors could exploit it, and the rescue became one of Ethereum’s most well-publicized white-hat rescue efforts.
Unlike the 2020 incident, the latest exploit resulted in real losses after attackers used weaknesses in bond validation and price logic to withdraw USDC from live currency pools. At press time, Lien Finance had not released a detailed technical postmortem or announced whether any of the stolen money had been frozen or recovered.



