Blockchain security firm SlowMist traced the breach to the exchangeEquivalentBonds function within the BondMakerCollateralizedEth contract. The vulnerability allowed the attacker to bypass integrity checks by repeatedly using the same bond ID in an output group, effectively satisfying validation requirements while omitting necessary input bonds. This enabled the creation of synthetic bond tokens that lacked genuine collateral, which were then exchanged for USDC through pre-authorized endpoints.
Additional analysis from DefimonAlerts and researcher exvulsec suggests the attacker deployed a custom orchestration contract to register a new bond group without requiring governance approval. This group, designed with a malicious payoff function, was subsequently routed into the protocol’s GeneralizedDotc over-the-counter pools. The internal pricing mechanism, _calcRateBondToErc20, reportedly assigned excessive value to these unbacked instruments, allowing the attacker to extract real liquidity.

Comments (0)
No comments yet. Be the first!