← Radar

Incident case file

Sign in to watch

Lien Finance — exchangeEquivalentBonds multiset integrity flaw

Incident date 2026-07-23Last updated Aug 12, 2026

7 views

ActiveEthereumSmart Contract Logic / Bond Token BugCluster: LIEN-BONDLOGIC-2026-07

Estimated loss

$542.1K

Victims identified

1
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

EOA: 0x0D7d9023531aD1A88414E216Ee2715F63561808a (Ethereum) | Orchestration contract (deployed by attacker): 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e | Pre-attack funded by CCE.Cash Exchange: 0.18854407 ETH

Funds moved to

~542,144.63 USDC drained from GeneralizedDotc OTC pools via 4 sequential interactions with orchestration contract (blocks 25599302) | Exploit tx: 0xb96d572b557a12f5ef193e88cca86123a6ae1b6e98b0eeee265870c85848e0e7 | Cash-out: 287.65576801 ETH sent to 0xcb2bFAe460C9915c4d4e5b70a59756CC5b2D87C8 (tx: 0x55686fed2ba276c105fc6b72153201f2abcf988a480936e2799e81b248491db2) | Attacker also used EIP-7702 MetaMask delegation (self-tx: 0x5505f6f2a3e3d6de9bdfa62eafa0f3ef4919566a2d1d935341ce1c1d25c39adb)

Linked

BondMakerCollateralizedEth contracts (vulnerable): 0xda6fc5625e617bb92f5359921d43321cebc6bef0 + 0x843225cf6e663e4454732d6b551a737ac7b47de0 | GeneralizedDotc LP victim: 0xA961684a3a654fb2cca8f8991226c0cefc514d80 | GeneralizedDotc pool (primary affected liquidity): 0x656e…9ef18 | Root cause (SlowMist/ExVul): exchangeEquivalentBonds verified total exception count rather than per-bondID presence; repeating a single bondID consumed counter twice, concealing missing input bond and allowing mint of unbacked BondTokens.

Chronology

1 beat
  1. On July 24, 2026, an attacker exploited a logic flaw in the Lien Finance protocol on Ethereum, draining approximately $542,144.63 USDC. The attacker first deployed an orchestration contract (0xe74d17c1...) from EOA 0x0D7d9023..., which had been funded by CCE.Cash Exchange with 0.18854407 ETH. The orchestration contract permissionlessly registered a crafted bond group on BondMakerCollateralizedEth with a malicious payoff function. The root cause (per SlowMist TI Alert): the exchangeEquivalentBonds function checked total exception occurrences rather than per-bondID presence within each group. By repeating a single bondID in the output exception list, the attacker consumed the exception counter twice, concealing a missing input bond and allowing the minting of unbacked BondTokens without burning corresponding input bonds. These unbacked tokens were then swapped via three pre-authorized GeneralizedDotc OTC pool endpoints, which overvalued the crafted bonds and released USDC liquidity. Four sequential exploit calls were executed in block 25599302. The attacker converted proceeds to 287.65576801 ETH (sent to 0xcb2bFAe...) and used EIP-7702 delegation. SlowMist issued a TI Alert the same day. No response from Lien Finance was published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)