← Lien Finance Bond Exploit (July 2026)3 decisions on this page
Audit log
Every state-changing event for Lien Finance Bond Exploit (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-29 12:46:46ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 443,502,742
- sig
2U6ANBq1WDzM…FW8uQkLwexplorer ↗- hash
4jTXk1stB5KT…bZEfD69isha256 → base58
verifying row…full verify ↗canonical bytes (14388 B) ▸
{"actor":"system:backfill","investigation_id":"73a3321a-cc8e-4ddc-8492-7393d29c4f78","kind":"publish","page_slug":"lien-finance-bond-exploit-july-2026","published_at":"2026-07-29T12:46:46.157Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lien Finance Bond Exploit (July 2026)","sections":[{"content":"On July 24, 2026, Lien Finance suffered a smart contract exploit that resulted in the theft of approximately 542,144.63 USDC from a liquidity provider's pre-authorized allowance. The attacker exploited a permissionless bond registration system combined with a flawed equivalence-check function to mint synthetic bond tokens without posting real collateral, then exchanged those tokens for genuine USDC through the protocol's GeneralizedDotc over-the-counter pools. The exploit was identified and flagged by on-chain analytics and security firms including SlowMist, Verichains, and DefimonAlerts within hours of occurrence. The attack occurred one day after a broader industry 'Hackers' Day' on July 23, 2026, in which three separate exploits totaled $35.55 million across AFX Trade, B2 Network, and Verus Bridge.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"},{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"},{"credibility":2,"name":"Lien Finance Suffers Attack Resulting in Approximately $542,000 Loss","type":"news_article","url":"https://www.odaily.news/en/newsflash/503527"}]},{"content":"Security researchers at Verichains and SlowMist identified two compounding design flaws that enabled the attack. The primary vulnerability resided in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth smart contract. This function was intended to enforce multiset equivalence between input and output bond groups, ensuring that bond IDs appeared the correct number of times in both sets. Instead, the implementation performed only aggregate count matching, allowing the attacker to repeat a flagged exception bondID multiple times in a single call to satisfy the check while omitting required bonds from the input set. This enabled minting of new, uncollateralized BondTokens without burning corresponding input bonds. The secondary vulnerability was located in the _calcRateBondToErc20 function of the GeneralizedDotc contract. This function priced bonds based solely on registered payoff functions without verifying actual collateral backing, allowing the attacker's synthetically minted bonds to be assigned inflated economic value when submitted to OTC pools. The attack sequence proceeded as follows: the attacker deployed an orchestration contract and permissionlessly registered a fraudulent bond group with artificially inflated pricing; exploited the exchangeEquivalentBonds flaw to mint new bond tokens without destroying the corresponding input instruments; submitted the overpriced synthetic bonds to the GeneralizedDotc OTC pool where a liquidity provider had pre-authorized spending; and received 542,144.63 USDC from that provider's allowance. Security researchers classified the attack as a protocol logic failure rather than a conventional memory-safety or reentrancy bug.","heading":"Exploit Mechanism and Technical Analysis","severity":"critical","sources":[{"credibility":2,"name":"LIEN FINANCE HACK ANALYSIS — Verichains","type":"research","url":"https://blog.verichains.io/p/lien-finance-hack-analysis"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"}]},{"content":"Blockchain forensic analysis identified the following on-chain actors and artifacts. The attacker's externally owned account (EOA) is 0x0D7d9023531aD1A88414E216Ee2715F63561808a. The orchestration contract deployed by the attacker to coordinate the exploit is 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e. The primary vulnerable contract (BondMakerCollateralizedEth) is at 0xDA6FC5625E617bB92F5359921D43321cEbC6BEf0; a second BondMakerCollateralizedEth contract at 0x843225cf6e663e4454732d6b551a737ac7b47de0 was also affected. The GeneralizedDotc OTC pool drained in the attack is at 0x656e5e976d523a427f05B0c212A22A89ccD9eF18. The funds were extracted from liquidity provider address 0xA961684a3a654fb2cCA8F8991226C0CEfc514d80, which had pre-authorized the OTC pool to spend its USDC. The primary exploit transaction hash is 0xb96d572b557a12f5ef193e88cca86123a6ae1b6e98b0eeee265870c85848e0e7. The exploit transaction was verified on Blockscout and circulated to exchanges and stablecoin issuers for monitoring purposes. No subsequent attacker on-chain messages or fund movement disclosures were documented as of late July 2026.","heading":"On-Chain Forensics and Key Addresses","severity":"critical","sources":[{"credibility":2,"name":"LIEN FINANCE HACK ANALYSIS — Verichains","type":"on_chain","url":"https://blog.verichains.io/p/lien-finance-hack-analysis"},{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"}]},{"content":"As of late July 2026, Lien Finance had not issued any public statement regarding the July 24 exploit. No post-mortem, incident disclosure, or patch announcement was published by the team. Multiple news outlets noted that the exploit pathway remained unpatched at the time of their reporting, leaving the protocol potentially vulnerable to copycat attacks. No bounty offer to the attacker, no recovery of stolen funds, and no communication from the Lien Finance team to affected liquidity providers was documented in available sources. The absence of any official response from the protocol has been noted as a concern by security researchers.","heading":"Protocol Response and Fund Recovery Status","severity":"high","sources":[{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"}]},{"content":"The July 2026 exploit is not the first security incident involving Lien Finance's bond architecture. In September 2020, security researcher Samczsun discovered a closely analogous flaw in Lien Finance's original BondMaker contract, which at the time held approximately 25,000 ETH (valued at roughly $9.6-10 million). The 2020 vulnerability similarly allowed the creation of empty bond groups that could be exchanged against valid, collateralized bond groups through the equivalence function, extracting Ether without real backing. Samczsun coordinated a white-hat rescue operation with ConsenSys Diligence researcher Alexander Wade, Ethereum security specialist Scott Bigelow, and SparkPool developers, who built a specialized transaction relay to move funds out of the vulnerable contract without exposing the transaction in the public mempool. The rescue succeeded and the funds were returned to the protocol. Security analysts commenting on the July 2026 exploit have noted the structural similarity between the 2020 and 2026 vulnerabilities, pointing to a recurring architectural pattern in Lien Finance's permissionless bond primitives as a systemic risk factor.","heading":"Historical Context: 2020 White-Hat Rescue","severity":"medium","sources":[{"credibility":2,"name":"Escaping the Dark Forest — samczsun.com","type":"research","url":"https://samczsun.com/escaping-the-dark-forest/"},{"credibility":3,"name":"Sep 2020 — Lien Finance Rescued — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/hackfraudscam/lienfinancerescued.php"},{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"}]},{"content":"The Lien Finance exploit occurred within an exceptionally active period for DeFi security incidents. July 2026 followed a stretch that had cost the DeFi ecosystem more than $630 million across the first seven months of 2026. On July 23, 2026, the day before the Lien Finance attack, three separate exploits totaling $35.55 million were recorded: AFX Trade ($24 million), B2 Network ($3.86 million), and Verus Bridge ($7.54 million). Other notable incidents during this period included Lazy Summer Protocol ($6.04 million), Bonzo Finance ($9 million), and Polychain-backed Cascade ($1.34 million). Security analysts identified oracle and price manipulation, bridge validation logic failures, and uncollateralized minting via permissionless registration as the leading attack vectors. The Lien Finance incident was categorized alongside similar protocol logic failures rather than more conventional attack classes such as reentrancy or flash loan manipulation.","heading":"Broader DeFi Security Context (July 2026)","severity":"medium","sources":[{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"}]}],"sources_used":[{"credibility":2,"name":"LIEN FINANCE HACK ANALYSIS — Verichains","type":"research","url":"https://blog.verichains.io/p/lien-finance-hack-analysis"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug — crypto.news","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"},{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"},{"credibility":2,"name":"Lien Finance Hacked for $542,000 in USDC Bond Exploit — CoinLaw","type":"news_article","url":"https://coinlaw.io/lien-finance-542000-usdc-bond-exploit/"},{"credibility":2,"name":"Lien Finance Suffers Attack Resulting in Approximately $542,000 Loss — Odaily","type":"news_article","url":"https://www.odaily.news/en/newsflash/503527"},{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"Escaping the Dark Forest — samczsun.com","type":"research","url":"https://samczsun.com/escaping-the-dark-forest/"},{"credibility":3,"name":"Sep 2020 — Lien Finance Rescued — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/hackfraudscam/lienfinancerescued.php"},{"credibility":2,"name":"Lien Finance Suffers $542,000 Attack — Bitcoin Sistemi","type":"news_article","url":"https://en.bitcoinsistemi.com/lien-finance-suffers-542-000-attack/"}],"summary":"On July 24, 2026, Lien Finance, an Ethereum-based structured products protocol for creating fixed-income instruments from ETH collateral, was exploited for approximately $542,144 USDC. An attacker abused a logic validation flaw in the protocol's bond exchange function to mint uncollateralized bond tokens and drain liquidity from the protocol's OTC pools. As of late July 2026, Lien Finance had issued no public statement and no funds had been reported recovered.","timeline":[{"date":"2020-09-15","event":"Security researcher Samczsun discovers a bond equivalence flaw in Lien Finance's original BondMaker contract holding ~25,000 ETH (~$10M). A coordinated white-hat rescue operation with ConsenSys and SparkPool successfully moves funds out of the vulnerable contract before any attacker acts.","source":"samczsun.com / Quadriga Initiative","source_url":"https://samczsun.com/escaping-the-dark-forest/"},{"date":"2026-07-23","event":"Industry 'Hackers' Day': three separate DeFi exploits totaling $35.55 million hit AFX Trade ($24M), B2 Network ($3.86M), and Verus Bridge ($7.54M) within 24 hours.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"date":"2026-07-24","event":"Attacker EOA 0x0D7d...1808a deploys orchestration contract, permissionlessly registers a fraudulent bond group, exploits the exchangeEquivalentBonds function in BondMakerCollateralizedEth to mint uncollateralized bond tokens, and drains 542,144.63 USDC from a pre-authorized liquidity provider via Lien Finance's GeneralizedDotc OTC pool. Exploit transaction: 0xb96d572b557a12f5ef193e88cca86123a6ae1b6e98b0eeee265870c85848e0e7.","source":"Verichains / crypto.news","source_url":"https://blog.verichains.io/p/lien-finance-hack-analysis"},{"date":"2026-07-24","event":"SlowMist, Verichains, and DefimonAlerts publicly identify and document the exploit. Exploit transaction circulated to exchanges and stablecoin issuers for monitoring. Protocol vulnerability reported as unpatched.","source":"crypto.news / CryptoTimes","source_url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"},{"date":"2026-07-24","event":"Lien Finance issues no public statement. No patch, post-mortem, bounty offer, or communication to affected users is documented as of late July 2026.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision f7e47ea7-7679-4291-9e1f-6f4b1498715a - #2reviewby reviewerreviewer2026-08-27 01:03:43ZScore: 10 → 10 (no score change)The page's core claims -- entity identity, exploit date/amount, technical mechanism, on-chain addresses, absence of an official response, and the 2020 historical precedent -- are all independently confirmed by primary and secondary sources, including a SlowMist alert not among the page's own cited sources. The main weaknesses found are contextual: the 'Hackers' Day' July 23 date is applied uniformly to an AFX Trade breach that at least one cited source dates a day earlier, the $630M year-to-date DeFi loss figure is reproduced from a single outlet's framing without noting that other trackers report substantially higher totals, and the 2020 rescue's participant list omits CertiK contributors credited in the page's own cited source. No disputed, unverifiable, or link-rot findings were identified; all cited live URLs resolved and supported their claims.anchoranchored
- chain
- ●mainnet-betaslot 443,522,664
- sig
4WM71yY5qGcR…3VCPUJrNexplorer ↗- hash
GNAFrXxzbrXF…Wt34sp8osha256 → base58
verifying row…full verify ↗canonical bytes (1232 B) ▸
{"actor":"reviewer","decided_at":"2026-08-27T01:03:43.537Z","decision":"review","investigation_id":"73a3321a-cc8e-4ddc-8492-7393d29c4f78","new_score":10,"page_slug":"lien-finance-bond-exploit-july-2026","prev_score":10,"reason":"The page's core claims -- entity identity, exploit date/amount, technical mechanism, on-chain addresses, absence of an official response, and the 2020 historical precedent -- are all independently confirmed by primary and secondary sources, including a SlowMist alert not among the page's own cited sources. The main weaknesses found are contextual: the 'Hackers' Day' July 23 date is applied uniformly to an AFX Trade breach that at least one cited source dates a day earlier, the $630M year-to-date DeFi loss figure is reproduced from a single outlet's framing without noting that other trackers report substantially higher totals, and the 2020 rescue's participant list omits CertiK contributors credited in the page's own cited source. No disputed, unverifiable, or link-rot findings were identified; all cited live URLs resolved and supported their claims.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8186997f-793b-41a8-b832-e2df4154c9e7 - #3review approveby judgejudge2026-08-27 01:03:43ZScore: 10 → 10 (no score change)Independent verification confirms the page's central claims hold up: the protocol is correctly identified and not confused with the similarly-named 'LienFi' project (claim_findings[0]), the exploit's date, amount, technical root cause, and on-chain addresses are all confirmed against primary security-firm analyses and independently corroborated by a SlowMist alert the page did not even cite (claim_findings[1]-[6]), and the 'no official response' framing was specifically re-checked through the current date rather than left stale (claim_findings[7]). Disputed_pct is 0.0% -- there are no disputed or unverifiable claims, no link rot, and no stale findings. The three partially_supported findings (claim_findings[9], [11], [12]) concern secondary context -- an incomplete credit list in a 2020 historical aside, a one-day date discrepancy for a different protocol's breach folded into an industry-wide 'Hackers' Day' tally, and an unqualified year-to-date DeFi loss figure -- none of which touch the page's core allegation against Lien Finance. No coverage gap is rated high priority, so no lever exists to push the page out of the approve band.anchoranchored
- chain
- ●mainnet-betaslot 443,522,673
- sig
4ztVMSwsjrFU…S7ZdXq2Zexplorer ↗- hash
JDvHMGFG89D8…AWbUwWoZsha256 → base58
verifying row…full verify ↗canonical bytes (1524 B) ▸
{"actor":"judge","decided_at":"2026-08-27T01:03:43.537Z","decision":"review_approve","investigation_id":"73a3321a-cc8e-4ddc-8492-7393d29c4f78","new_score":10,"page_slug":"lien-finance-bond-exploit-july-2026","prev_score":10,"reason":"Independent verification confirms the page's central claims hold up: the protocol is correctly identified and not confused with the similarly-named 'LienFi' project (claim_findings[0]), the exploit's date, amount, technical root cause, and on-chain addresses are all confirmed against primary security-firm analyses and independently corroborated by a SlowMist alert the page did not even cite (claim_findings[1]-[6]), and the 'no official response' framing was specifically re-checked through the current date rather than left stale (claim_findings[7]). Disputed_pct is 0.0% -- there are no disputed or unverifiable claims, no link rot, and no stale findings. The three partially_supported findings (claim_findings[9], [11], [12]) concern secondary context -- an incomplete credit list in a 2020 historical aside, a one-day date discrepancy for a different protocol's breach folded into an industry-wide 'Hackers' Day' tally, and an unqualified year-to-date DeFi loss figure -- none of which touch the page's core allegation against Lien Finance. No coverage gap is rated high priority, so no lever exists to push the page out of the approve band.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision ee024e05-0250-46b4-8ba8-abf3067bc6fd
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.