Lien Finance Hit by $542K Exploit Tied to Bond Token Logic Bug
Lien Finance lost $542,000 in USDC after an attacker exploited a flaw in its bond token exchange logic. The security researchers at SlowMist identified the vulnerability as being located in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract.
The issue allowed attackers to mint new BondTokens that appeared valid even though no matching collateral had been consumed. These newly created assets were then exchanged for USDC through three pre-authorized endpoints, resulting in the withdrawal of $542,144.63 from the victim address 0xa961684a3a654fb2cca8f8991226c0cefc514d80.
The attack relied on introducing synthetic financial instruments whose economic value was not sufficiently validated before they became eligible for OTC swaps.