LianGo Protocol Hack

REPORTED LOSS $1.6M
Medium Access Control

What happened

A suspected compromise of the LGTPool owner key let the attacker register a malicious LP pool on BNB Smart Chain. Using attacker-controlled fake LP tokens, the attacker drained 6.15 million LGT and swapped it for about $1.63 million in BSC-USD.

Case & protocol details

Classification Token
Protocol Type Exploit/Access control
Affected asset / contract LGT
Official Website liangopro.com/
Protocol Twitter/X @LianGoProtocol

How it happened

The LGTPool owner added a new pool whose LP token address pointed to an attacker-controlled contract. That token's transferFrom call always succeeded, allowing the attacker to deposit an arbitrary amount of fake LP tokens into the new pool. The attacker then increased the fake token supply and withdrew the pool's LGT rewards before swapping them for BSC-USD.

CertiK and Halborn concluded that the owner authority was likely compromised, so this was an abuse of privileged control rather than an unauthenticated access-control bypass.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.