Lien Finance Hit by $542K Exploit Tied to Bond Token Logic Bug
Lien Finance has suffered a loss of $542,144.63 in USDC after an attacker exploited a flaw in its bond token exchange logic.
The attack allowed unsupported bond tokens to be minted and exchanged for real liquidity from the protocol. This is the latest incident in a string of DeFi exploits this month.
According to SlowMist, the vulnerability was located in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract. The function failed to properly verify the integrity of bond groups during exchanges.
The attacker was able to mint new BondTokens that appeared valid even though no matching collateral had been consumed. These tokens were then exchanged for USDC through three pre-authorized endpoints, resulting in the withdrawal of $542,144.63 from the victim address.