Lendf.me Hack

TOTAL LOST $25.2M
High Reentrancy Ethereum

What happened

Lendf.Me, dForce's Ethereum lending protocol, was drained through an ERC-777 reentrancy flaw involving imBTC. The attacker inflated recorded imBTC collateral through the token's callback behavior, then borrowed assets from more than ten liquidity pools. dForce later confirmed that all stolen assets were recovered and users were made whole.

Technical Root Cause

Lendf.Me allowed a callback-capable ERC-777 token to invoke external control flow during deposit processing without comprehensive reentrancy protection. Its balance-accounting flow did not safely commit state before the token transfer interaction, enabling stale collateral values to overwrite the withdrawal result.

Case & protocol details

Classification Reentrancy / Collateral Accounting
Protocol Type Exploit/Other
Affected asset / contract USDx
Smart Contract Language Solidity
Official Website lendf.me/
Protocol Twitter/X @lendfme

Attack Timeline

The attacker interacted with Lendf.Me using imBTC, an ERC-777-compatible token. During token-transfer processing in supply(), the ERC-777 callback enabled a reentrant withdraw() before Lendf.Me finalized the user's balance update. The reentrant path withdrew collateral while the outer supply() call later wrote a stale, higher balance back to storage.

Repeating the cycle inflated the attacker's recorded collateral, allowing borrowing of the protocol's available WETH, stablecoins, BTC-related assets, and other tokens. The related April 18 Uniswap imBTC incident used the same callback family but was a separate exploit and must not be conflated with this lending-market drain.

Funds Recovery

100.0%

Recovered

$25.2M

Net Loss

$0

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.