Incident case file
Sign in to watchLikwid LikwidMarginPosition Bug — 74.31 BNB Gross, $9,240 Net LP Loss
1 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 18, 2026, an attacker exploited a bug in LikwidMarginPosition's leverage=0 (collateral-borrow) branch: the code never assigned delta.pairDelta, leaving pool reserves unchanged across repeated calls, so the same price quote was returned 14 times regardless of actual pool state. The attacker first spent about 5 minutes pumping a thin BNB/meme-token pool's price 4.6x using ~55 BNB of their own capital, then opened 24 collateral-borrow positions against the inflated token price in a single transaction, extracting 74.310377809898883696 BNB (~$55,825-56,183 at the time). Likwid's own published reconciliation clarified that this gross figure is misleading: 55 BNB of the 74.31 was the attacker's own money recycled through the pump, and a prior failed attempt 80 minutes earlier had already lost 20.44 BNB to the pool's dynamic fee mechanism. The attacker's true net profit was only +2.19 BNB (~$1,645). The pool's real liquidity dropped from 17.93 to 5.67 BNB — a loss to LPs of approximately 12.3 BNB (~$9,240), with 2.19 BNB captured by the attacker and the remainder absorbed by third-party trades exploiting the inflated price. Within roughly two hours, the attacker's wallet was drained via Tornado Cash and FixedFloat, ending with a balance of 0.6258 BNB. Likwid raised the minimum collateral ratio for this mode from 1.4x to 16.78x within hours as an emergency mitigation and announced the collateral-borrow feature will be removed entirely in a future contract version.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)