Lien Hack

Reported loss $542K
Ethereum
Bond Group Validation Flaw

What happened

A July 24, 2026 SlowMist report describes a Lien Finance exploit involving approximately $542,000 in USDC. Its analysis attributes the loss to incomplete bond-group validation that enabled unbacked bond issuance and withdrawals through OTC pools.

How it happened

SlowMist identified missing multiset checks in exchangeEquivalentBonds: counting exceptions did not establish that each bond identifier appeared in the required group. The attacker used repeated identifiers to obtain unbacked bonds.

Protocol details

Classification Input Validation
Protocol Type Options
Implementation language Solidity
Protocol links Website @LienFinance

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.