Revoke.cash logo

Lien Finance Hack

Check if your address is affected.

24 Jul 2026
$540k stolen
Ethereum Logo

Lien Finance is a DeFi protocol from 2020 that let people create and trade bond-like financial products on Ethereum. It was abandoned long ago, but its contracts stayed live and were never patched. On 24 July 2026, an attacker registered a new type of bond, which anyone was allowed to do, and used a flaw to create bond tokens that were worth almost nothing. Lien's trading pools priced these fake bonds far above their real value, so the attacker could swap them for real USDC.

The attacker took around $542k in USDC. The pools did not hold this USDC themselves: it came from liquidity providers who had approved the pools to spend it on their behalf. At the time of reporting, Lien Finance had not made any public statement, and no stolen funds were reported frozen or returned. This was not the protocol's first close call. In September 2020, a group of whitehat researchers including samczsun rescued around $10M from an earlier version of Lien's bond system after finding a different flaw.

Nobody is maintaining Lien Finance, and its contracts remain unpatched, so any approvals that are still in place stay at risk. If you ever provided liquidity to Lien Finance or approved any of its contracts, check your wallet on Ethereum and revoke those approvals, especially for USDC. Revoking protects the funds that are still in your wallet, but it does not recover what was already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits