Lien Finance's bond-to-ERC20 OTC pools drained for $542K via oracle price manipulation and permissionless bond registration.
Security & Exploits ·
Lien Finance's bond-to-ERC20 over-the-counter pools lost approximately $542,000 USDC in an exploit involving oracle price manipulation. An attacker deployed a contract that registered new bond groups without permission on the BondMakerCollateralizedEth contract, then used a crafted payoff function to manipulate the bond pricing mechanism. The attacker then swapped these artificially inflated bonds through the GeneralizedDotc pools in exchange for the full USDC allowance that a liquidity provider had granted to the pools.
The vulnerability centered on the bond pricing calculation, which relied on oracle prices and volatility metrics to determine the exchange rate between newly minted bonds and USDC. By controlling the bond's parameters through the permissionless registration process, the attacker was able to inflate the reported bond price relative to its actual collateral backing. This caused the pools to exchange worthless or significantly undervalued bonds at rates that drained the available liquidity.
The mechanism exploited a gap between bond registration permissions and pricing validation. It remains unclear whether oracle manipulation alone drove the price inflation, how the payoff function parameters specifically distorted valuations, or what governance or technical remedies Lien Finance intends to implement to prevent similar attacks on its collateralized bond infrastructure.