← Lien Finance1 decision on this page
Audit log
Every state-changing event for Lien Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-24 23:08:38ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
AiG8ZrrzuTkv…jivDjt8Asha256 → base58
verifying row…canonical bytes (13510 B) ▸
{"actor":"system:backfill","investigation_id":"8beab549-0d90-45fa-93a8-6d78e0c6e9a4","kind":"publish","page_slug":"lien-finance","published_at":"2026-07-24T23:08:38.363Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lien Finance","sections":[{"content":"On July 24, 2026, Lien Finance's GeneralizedDotc OTC pools were exploited for approximately 542,144.63 USDC. According to reporting by Crypto Times and crypto.news, the attacker first deployed an orchestration contract at address 0xe74...8062e, then exploited the protocol's open, permissionless bond group registration system to introduce a malicious bond group with a crafted payoff function. Because the BondMakerCollateralizedEth contract's exchangeEquivalentBonds function did not verify that each required bond ID appeared the correct number of times — only counting total exception entries — the attacker satisfied validation logic while minting BondTokens backed by no real collateral. These fabricated bond tokens were then exchanged for USDC through three pre-authorized OTC endpoints, with real liquidity withdrawn from the victim address 0xa961684a3a654fb2cca8f8991226c0cefc514d80. Security researchers, including the on-chain monitor exvulsec, categorized the incident as an oracle and price manipulation exploit, with the root vulnerability located at the intersection of unrestricted bond registration and flawed rate calculation in the _calcRateBondToErc20 function. The incident was first flagged publicly by DefimonAlerts and subsequently verified by SlowMist. No funds are alleged to have been recovered as of the date of reporting.","heading":"July 2026 Exploit — $542K USDC Drained","severity":"critical","sources":[{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug — crypto.news","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"}]},{"content":"The 2026 exploit exploited two compounding design weaknesses in the Lien protocol architecture. First, Lien's bond registration is permissionless: any actor can register a new bond group on BondMakerCollateralizedEth without governance approval or collateral verification, allowing the introduction of economically invalid bond groups. Second, the _calcRateBondToErc20 rate calculation function did not sufficiently validate the economic realism of the underlying bond payoff structure before authorizing OTC pool swaps. The exchangeEquivalentBonds function's flawed validation — counting total exception entries rather than verifying each required bond ID appeared the required number of times — allowed the attacker to reuse a single exception bond ID in output groups while omitting required input bonds. The net result was that minted BondTokens carried no collateral backing but were accepted by the OTC pool at inflated valuations, enabling the drainage of real USDC liquidity. Researchers noted the structural similarity between this exploit and the protocol's 2020 incident, in which empty bond groups could be exchanged against valid, collateralized bond groups through an equivalence function.","heading":"Technical Vulnerability Analysis","severity":"critical","sources":[{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug — crypto.news","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"},{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"}]},{"content":"On or around September 15–16, 2020, a whitehat coalition that included security researcher samczsun, Alexander Wade of ConsenSys Diligence (one of the protocol's two auditors), and Ethereum security specialist Scott Bigelow identified a critical vulnerability in Lien Finance's original BondMaker contract. The flaw allowed creation of empty bond groups that could be exchanged against valid, collateralized bond groups through the protocol's equivalence function, enabling extraction of ETH without real backing. At the time, the vulnerable contract held approximately 25,000 ETH, valued at roughly $9.6–10 million. The whitehats executed a coordinated rescue operation and moved funds to safety before any malicious actor could exploit the vulnerability. All user funds were returned and no losses were incurred. The event was widely reported as a landmark case of coordinated whitehat intervention in Ethereum's mempool. Lien Finance subsequently published an incident analysis on its Medium channel. The 2020 incident and the 2026 exploit share a structurally similar root cause: the protocol's bond equivalence and exchange logic failed to enforce adequate collateral integrity checks.","heading":"Prior Security Incident — September 2020 Whitehat Rescue","severity":"high","sources":[{"credibility":2,"name":"Sep 2020 — Lien Finance Rescued — $9.6M — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/hackfraudscam/lienfinancerescued.php"},{"credibility":2,"name":"Interruption of Service — Incident Analysis — Lien Protocol on Medium","type":"official","url":"https://medium.com/lien-finance/interruption-of-service-incident-analysis-32077389c13"},{"credibility":2,"name":"Whitehat hacker Saves 25,000 ETH From Vulnerable Ether Smart Contract — KryptoMoney","type":"news_article","url":"https://www.kryptomoney.com/whitehat-hacker-saves-25000-eth-from-vulnerable-ether-smart-contract/"}]},{"content":"Lien Finance is a governance-free DeFi protocol on Ethereum that launched on mainnet in August 2020, following publication of its iDOL stablecoin whitepaper in April 2020 and two independent smart contract audits by ConsenSys Diligence and CertiK. The protocol's core mechanism tranches ETH deposits into two derivative tokens: SBT (Solid Bond Token), which is relatively stable and redeemable at a fixed dollar value at maturity, and LBT (Liquid Bond Token), which absorbs ETH price volatility and behaves analogously to a leveraged call option. The LIEN utility token entitles holders to fee discounts on the protocol and FairSwap. The total supply of LIEN is approximately 1.09 million tokens, with a circulating supply of approximately 553,502. As of early 2026, LIEN traded at approximately $0.053 with negligible 24-hour volume, indicating significantly reduced market activity and liquidity relative to the protocol's earlier periods. The development team has been described as anonymous, with backgrounds in traditional financial derivatives. No named founders or executives have been confirmed in publicly available sources.","heading":"Protocol Background and Token Status","severity":"medium","sources":[{"credibility":2,"name":"What is Lien (LIEN)? — Coinranking","type":"other","url":"https://coinranking.com/coin/kE0BUPLLo+lien-lien/about"},{"credibility":2,"name":"Lien Token — LIEN — Lien.finance (official)","type":"official","url":"https://lien.finance/lien"},{"credibility":2,"name":"Lien Protocol — Stablecoin Without Governance — DeFi Prime","type":"research","url":"https://defiprime.com/lien"}]},{"content":"The Lien Finance exploit occurred during a period of elevated DeFi exploit activity in July 2026. According to altfins.com, cumulative DeFi losses across the sector exceeded $840 million through mid-2026. The Lien incident followed a series of exploits in the preceding 24 hours on July 23, 2026, including a $24 million drain of AFX Trade's Arbitrum bridge, a $3.86 million loss at B2 Network, and a $7.54 million exploit of the Verus Ethereum Bridge. While comparatively smaller in scale, the Lien Finance incident represents a distinct new event with the same underlying structural pattern seen across multiple 2026 DeFi exploits: introduction of a synthetic instrument whose value is mispriced by the protocol, followed by extraction of genuine liquidity against it.","heading":"Broader DeFi Exploit Context — July 2026","severity":"medium","sources":[{"credibility":2,"name":"DeFi Hacks 2026: $840M+ Lost and the Attack That Changed Everything — AltFins","type":"research","url":"https://altfins.com/blog/defi-hacks-2026/"},{"credibility":2,"name":"Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/"}]}],"sources_used":[{"credibility":2,"name":"Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/ethereum-defi-protocol-lien-finance-hacked-for-542k-in-usdc-exploit/"},{"credibility":2,"name":"Lien Finance hit by $542K exploit tied to bond token logic bug — crypto.news","type":"news_article","url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"},{"credibility":2,"name":"Interruption of Service — Incident Analysis — Lien Protocol on Medium","type":"official","url":"https://medium.com/lien-finance/interruption-of-service-incident-analysis-32077389c13"},{"credibility":2,"name":"Sep 2020 — Lien Finance Rescued — $9.6M — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/hackfraudscam/lienfinancerescued.php"},{"credibility":2,"name":"Whitehat hacker Saves 25,000 ETH From Vulnerable Ether Smart Contract — KryptoMoney","type":"news_article","url":"https://www.kryptomoney.com/whitehat-hacker-saves-25000-eth-from-vulnerable-ether-smart-contract/"},{"credibility":2,"name":"What is Lien (LIEN)? — Coinranking","type":"other","url":"https://coinranking.com/coin/kE0BUPLLo+lien-lien/about"},{"credibility":2,"name":"Lien Token — LIEN — Lien.finance (official)","type":"official","url":"https://lien.finance/lien"},{"credibility":2,"name":"Lien Protocol — Stablecoin Without Governance — DeFi Prime","type":"research","url":"https://defiprime.com/lien"},{"credibility":2,"name":"DeFi Hacks 2026: $840M+ Lost and the Attack That Changed Everything — AltFins","type":"research","url":"https://altfins.com/blog/defi-hacks-2026/"},{"credibility":2,"name":"Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/"}],"summary":"Lien Finance is a governance-free Ethereum DeFi protocol launched in August 2020 that enables users to create options and stablecoins by tranching ETH deposits into two derivative bond tokens (SBT and LBT). On July 24, 2026, the protocol was exploited for approximately 542,144 USDC through manipulation of its permissionless bond registration system and a flawed OTC pricing function. This is the protocol's second significant security incident, following a September 2020 near-miss in which a whitehat coalition rescued approximately $10 million from a related BondMaker contract vulnerability.","timeline":[{"date":"2020-04-01","event":"Lien Finance publishes its initial whitepaper covering the iDOL stablecoin design.","source":"Coinranking — What is Lien (LIEN)?","source_url":"https://coinranking.com/coin/kE0BUPLLo+lien-lien/about"},{"date":"2020-08-01","event":"Lien Protocol launches on Ethereum mainnet following audits by ConsenSys Diligence and CertiK. LIEN tokens distributed via airdrop to early contributors and beta testers.","source":"Coinranking — What is Lien (LIEN)?","source_url":"https://coinranking.com/coin/kE0BUPLLo+lien-lien/about"},{"date":"2020-09-15","event":"Security researcher samczsun identifies a critical vulnerability in Lien Finance's BondMaker contract, which holds approximately 25,000 ETH (~$10M). A whitehat coalition including samczsun, ConsenSys Diligence researcher Alexander Wade, and Scott Bigelow executes a rescue operation, moving all user funds to safety before exploitation. No funds are lost.","source":"Sep 2020 — Lien Finance Rescued — Quadriga Initiative","source_url":"https://www.quadrigainitiative.com/hackfraudscam/lienfinancerescued.php"},{"date":"2020-09-16","event":"Lien Finance publishes an incident analysis on Medium acknowledging the BondMaker contract vulnerability and confirming all user funds were returned.","source":"Interruption of Service — Incident Analysis — Lien Protocol on Medium","source_url":"https://medium.com/lien-finance/interruption-of-service-incident-analysis-32077389c13"},{"date":"2026-07-24","event":"Lien Finance's GeneralizedDotc OTC pools are exploited for 542,144.63 USDC. The attacker registers a malicious bond group using the protocol's permissionless bond registration, mints uncollateralized BondTokens by exploiting flawed validation in the exchangeEquivalentBonds function, then swaps fabricated bonds for real USDC via three pre-authorized OTC endpoints. The incident is first flagged by DefimonAlerts and amplified by exvulsec and SlowMist.","source":"Lien Finance hit by $542K exploit tied to bond token logic bug — crypto.news","source_url":"https://crypto.news/lien-finance-hit-by-542k-exploit-tied-to-bond-token-logic-bug/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision f78aeba0-aa6c-4392-83f9-72d1ca777408
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.