Blockchain security firm SlowMist traced the breach to the exchangeEquivalentBonds function within the BondMakerCollateralizedEth contract. The vulnerability allowed the attacker to bypass integrity checks by repeatedly using the same bond ID in an output group, effectively satisfying validation requirements while omitting necessary input bonds. This enabled the creation of synthetic bond tokens that lacked genuine collateral, which were then exchanged for USDC through pre-authorized endpoints.
Additional analysis from DefimonAlerts and researcher exvulsec suggests the attacker deployed a custom orchestration contract to register a new bond group without requiring governance approval. This group, designed with a malicious payoff function, was subsequently routed into the protocol’s GeneralizedDotc over-the-counter pools. The internal pricing mechanism, _calcRateBondToErc20, reportedly assigned excessive value to these unbacked instruments, allowing the attacker to extract real liquidity.
This incident mirrors a pattern of valuation-based exploits seen elsewhere in the DeFi sector, including the Drift Protocol attack earlier this year. The event marks another setback for the Lien Finance architecture, which previously faced scrutiny in 2020 when security researchers intervened to prevent a potential $10 million loss. As of now, the protocol has not issued a formal postmortem or provided details on potential fund recovery.

Comments (0)
No comments yet. Be the first!