Lien Finance Suffers Attack Resulting in Approximately $542,000 Loss; Attacker Exploits Vulnerability to Drain USDC
According to SlowMist monitoring, the decentralized finance protocol Lien Finance suffered an attack. The attacker exploited a smart contract vulnerability to mint unbacked bond tokens and stole approximately $542,000 worth of USDC. Leveraging this vulnerability, the attacker successfully minted new, non-anomalous BondTokens without burning the corresponding input bonds. Subsequently, the attacker exchanged the tokens for USDC via a pre-authorized address, ultimately transferring approximately 542,144.63 USDC from the victim's address. Analysis indicates that the incident was essentially caused by a verification flaw in the bond token exchange logic, which allowed the attacker to bypass asset collateral constraints and mint unsupported assets.
