Lien Finance Suffers $542K Loss Due to Smart Contract Validation Flaw
Lien Finance, an Ethereum-based DeFi protocol, has lost approximately $542,144 in USDC after attackers exploited a smart contract validation flaw. The exploit targeted the exchangeEquivalentBonds function in Lien Finance's BondMakerCollateralizedEth contract.
According to SlowMist, the attack was made possible by a weakness in the contract's validation logic. The function failed to properly verify the integrity of bond groups during exchanges, allowing attackers to mint unbacked bond tokens and exchange them for USDC liquidity from Lien Finance's over-the-counter pools.
The affected contracts included BondMakerCollateralizedEth and related exchange infrastructure, while the drained funds originated from a liquidity provider's pre-approved USDC allowances rather than directly from users' wallets.