Lien Hack
What happened
A July 24, 2026 SlowMist report describes a Lien Finance exploit involving approximately $542,000 in USDC. Its analysis attributes the loss to incomplete bond-group validation that enabled unbacked bond issuance and withdrawals through OTC pools.
How it happened
SlowMist identified missing multiset checks in exchangeEquivalentBonds: counting exceptions did not establish that each bond identifier appeared in the required group. The attacker used repeated identifiers to obtain unbacked bonds.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.