← Radar

Incident case file

Sign in to watch

Lien Finance — exchangeEquivalentBonds multiset integrity flaw

Incident date July 24, 2026

2 views

ActiveEthereumSmart Contract Logic / Bond Token BugCluster: LIEN-BONDLOGIC-2026-07

Estimated loss

$542.1K

Victims identified

1
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: EOA: 0x0D7d9023531aD1A88414E216Ee2715F63561808a (Ethereum) | Orchestration contract (deployed by attacker): 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e | Pre-attack funded by CCE.Cash Exchange: 0.18854407 ETH

Funds moved to: ~542,144.63 USDC drained from GeneralizedDotc OTC pools via 4 sequential interactions with orchestration contract (blocks 25599302) | Exploit tx: 0xb96d572b557a12f5ef193e88cca86123a6ae1b6e98b0eeee265870c85848e0e7 | Cash-out: 287.65576801 ETH sent to 0xcb2bFAe460C9915c4d4e5b70a59756CC5b2D87C8 (tx: 0x55686fed2ba276c105fc6b72153201f2abcf988a480936e2799e81b248491db2) | Attacker also used EIP-7702 MetaMask delegation (self-tx: 0x5505f6f2a3e3d6de9bdfa62eafa0f3ef4919566a2d1d935341ce1c1d25c39adb)
BondMakerCollateralizedEth contracts (vulnerable): 0xda6fc5625e617bb92f5359921d43321cebc6bef0 + 0x843225cf6e663e4454732d6b551a737ac7b47de0 | GeneralizedDotc LP victim: 0xA961684a3a654fb2cca8f8991226c0cefc514d80 | Root cause (SlowMist/ExVul): the exchangeEquivalentBonds function verified total exception count rather than per-bondID appearance within each group — repeating a single bondID in the output exception list consumed the counter twice, hiding a missing input bond and allowing mint of un

Timeline: On July 24, 2026, an attacker exploited a logic flaw in the Lien Finance protocol on Ethereum, draining approximately $542,144.63 USDC. The attacker first deployed an orchestration contract (0xe74d17c1...) from EOA 0x0D7d9023..., which had been funded by CCE.Cash Exchange with 0.18854407 ETH. The orchestration contract permissionlessly registered a crafted bond group on BondMakerCollateralizedEth with a malicious payoff function. The root cause (per SlowMist TI Alert): the exchangeEquivalentBonds function checked total exception occurrences rather than per-bondID presence within each group. By repeating a single bondID in the output exception list, the attacker consumed the exception counter twice, concealing a missing input bond and allowing the minting of unbacked BondTokens without burning corresponding input bonds. These unbacked tokens were then swapped via three pre-authorized GeneralizedDotc OTC pool endpoints, which overvalued the crafted bonds and released USDC liquidity. Four sequential exploit calls were executed in block 25599302. The attacker converted proceeds to 287.65576801 ETH (sent to 0xcb2bFAe...) and used EIP-7702 delegation. SlowMist issued a TI Alert the same day. No response from Lien Finance was published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)