Lien Protocol Exploited for $542K Due to Missing Multiset Integrity Checks
2026-07-24 15:32

Woofun AI reports that Lien protocol suffered an exploit resulting in approximately $542,000 in losses. The vulnerability stemmed from inadequate multiset integrity checks within the `exchangeEquivalentBonds` function of BondMakerCollateralizedEth. This function tallied exception counts without verifying individual bondID occurrences, enabling attackers to duplicate a single abnormal bondID. By masking missing input exceptions through this duplication, attackers minted new, non-abnormal BondTokens without destroying corresponding inputs. These illicit tokens were subsequently exchanged for USDC from pre-authorized victim addresses.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
USDC
慢雾
Lien
BondMakerCollateralizedEth
BondTokens
Foresight News
Share:
back