Login
Sign Up
Woofun AI reports that Lien protocol suffered an exploit resulting in approximately $542,000 in losses. The vulnerability stemmed from inadequate multiset integrity checks within the `exchangeEquivalentBonds` function of BondMakerCollateralizedEth. This function tallied exception counts without verifying individual bondID occurrences, enabling attackers to duplicate a single abnormal bondID. By masking missing input exceptions through this duplication, attackers minted new, non-abnormal BondTokens without destroying corresponding inputs. These illicit tokens were subsequently exchanged for USDC from pre-authorized victim addresses.