LND Finance DPRK Worker Upgrades Contract Drains Funds

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

LND Finance Logo/Homepage Archive

LNDfi is a non-custodial, multichain money market platform designed to enhance capital efficiency and liquidity access through modular borrowing and lending mechanisms, including overcollateralized and flash loans. Despite its emphasis on risk management, transparency, and interoperability, the platform was compromised after inadvertently hiring a DPRK-affiliated worker who introduced a backdoor into critical smart contracts. This allowed any address with Pool Admin privileges to bypass standard access controls and drain funds. The exploit resulted in a loss of approximately $1.18–$1.27 million, prompting LNDfi to shut down its platform, alert users, and begin investigations with law enforcement and security teams. Although a 15% white-hat bounty has been offered, the likelihood of fund recovery remains slim given the attack’s origin.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17]

About LND Finance

LNDfi is a non-custodial, modular money market platform engineered to improve capital efficiency and expand liquidity access across a wide array of digital assets. Its design enables seamless borrowing and lending while offering users a flexible framework for effective risk management. Operating in a multichain environment, LNDfi facilitates integration across various blockchain networks, which strengthens interoperability and broadens the availability of liquidity.

The protocol allows users to participate in financial operations through several core mechanisms. Liquidity providers can supply assets to the platform, contributing to market depth and earning passive yields based on the protocol’s utilization rates. Borrowers, on the other hand, have access to liquidity via two main borrowing models: overcollateralized loans that require securing assets to reduce risk, and flash loans, which are instantaneous, uncollateralized loans executed within a single transaction for specialized strategies like arbitrage and liquidations.

Risk management is central to LNDfi’s infrastructure, with advanced analytics and real-time assessment tools designed to help users monitor and mitigate exposure. The protocol prioritizes security, transparency, and scalability by leveraging blockchain’s inherent strengths. Its mission is to democratize financial access and enhance the decentralized finance ecosystem through flexible asset support and seamless integration with other DeFi platforms, ensuring both adaptability and user safety.

The Reality

According to LND Finance, they accidentally hired a DPRK worker as part of their team. It appears that this worker made modifications to the AToken and VariableDebtToken portions of the smart contract, and also retained deployer access. These two factors combined to place the smart contract in a vulnerable position where it could be drained.

What Happened

"LNDFi's Pool Admin role fell into the wrong hands"

Key Event Timeline - LND Finance DPRK Worker Upgrades Contract Drains Funds
Date Event Description
March 29th, 2025 3:51:06 PM MDT Deployer Becomes Pool Admin The deployer became the Pool Admin role at txn 0xd03b…a41a.
March 29th, 2025 3:52:23 PM MDT Deployer Initializes New Contracts The deployer initialized the modified AToken contract.
March 29th, 2025 3:52:51 PM MDT Deployer Initializes New Contracts The deployer initialized the modified VariableDebtToken contract.
April 7th, 2025 2:55:06 AM MDT LND Finance Homepage Captured The LND Finance homepage is captured for the first time.
May 8th, 2025 8:29:09 PM MDT Fund Draining Starts Happening The deployer started draining all pools and deposited most funds to 0x5149…2cdd via a series of transferUnderlyingTo invocations, starting from txn 0xd52f…bffe.
May 8th, 2025 8:39:22 PM MDT Fund Bridging Starts Happening 0x5149…2cdd started bridging the stolen funds via a series of txns, started from txn 0xb287…8ee0. Most stolen funds were later bridge again.
May 8th, 2025 10:59:00 PM MDT LND Finance Posts Announcement LND Finance posts an announcement that they have detected a security issue, and recommends that users not deposit into the website.
May 9th, 2025 2:56:00 AM MDT LND Finance Shuts Down Site LND Finance reports that they are shutting down the website, because there are still people who are depositing and placing their funds at risk.
May 9th, 2025 3:19:36 AM MDT Pool Admin Permissions Revoked The deployer Pool Admin role was revoked by 0xe82e…aba4 at txn 0x74fa…b913.
May 13th, 2025 1:07:00 AM MDT Michael Mai Postmortem Released Michael Mai releases a postmortem on Twitter/X.
May 15th, 2025 7:11:28 AM MDT LND Finance Postmortem Released LND Finance publishes their post-mortem.
May 15th, 2025 7:46:00 AM MDT ZachXBT Clarifies Their Role ZachXBT clarifies that they "helped initially attribute the incident to DPRK IT workers and flagged theft addresses" but also that they are "not formally engaged nor creating an investigative report for" LND Finance.

Technical Details

"A carefully orchestrated contract modification, deployed 41 days before the heist, transformed pool management functions into an express lane for outbound funds.

The exploit didn’t rely on obscure math or oracle manipulation - just one extra condition in a core access check, giving any “Pool Admin” the ability to drain user funds."

"The deployer created a modified AToken contract (0xaa8cc9afe14f3a2b200ca25382e7c87cd883a527) where the onlyPool access control modifier was altered to allow not only the Pool contract but also any address with the Pool Admin role to invoke restricted functions."

"In original AAVE, only Pool can invoke transferUnderlyingTo and Pool Admin cannot. However, since onlyPool modifier was compromised, this is now possible."

Total Amount Lost

The LND Finance website presently reports the issue as "the loss of $1.27M funds".

Rekt News reports as "$1.18 million".

The total amount lost has been estimated at $1,270,000 USD.

Immediate Reactions

LND Finance posted an update on Twitter/X:

"We have detected a security issue on our platform. Please do NOT deposit into the platform it has been compromised. We are in talks with security teams to look into it further."

Ultimate Outcome

The LND Finance website is presently offline. It is unclear what lies ahead for affected users.

Total Amount Recovered

LND Finance appears to be attempting to recover the funds through investigation and legal recourse.

"We have communicated with the exploiter via an on-chain message, offering a 15% white-hat bounty in exchange for the return of the stolen funds. Should they choose to comply, 100% of the recovered amount will be distributed to affected users."

There do not appear to have been any funds recovered in this case.

Ongoing Developments

"We are actively investigating the incident with law enforcement and security partners to recover/freeze stolen funds.

Further updates will be shared on our community telegram group."

Given that the exploit was performed by DPRK, it is unlikely that any bounty will be accepted.

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. LNDFI - REKT (Accessed May 16, 2025)
  2. LND Finance - "We have detected a security issue on our platform. Please do NOT deposit into the platform it has been compromised. We are in talks with security teams to look into it further." - Twitter/X (Accessed May 16, 2025)
  3. LND Finance - "We are temporarily shutting down the website as people are still depositing." - Twitter/X (Accessed May 16, 2025)
  4. LND Finance - "Announcing the Official Launch of LNDfi! ... This is just the beginning of our journey." - Twitter/X (Accessed May 16, 2025)
  5. LND Finance - "We deployed 200+ contracts on @SonicLabs mainnet for testing" - Twitter/X (Accessed May 16, 2025)
  6. LND Postmortem - HackMD (Accessed May 16, 2025)
  7. LND Finance Homepage Archive April 7th, 2025 2:55:06 AM MDT (Accessed May 16, 2025)
  8. Parked Domain Prior To LND Finance Launch January 25th, 2025 7:57:33 AM MST (Accessed May 16, 2025)
  9. LND Finance Introduction - Gitbook (Accessed May 16, 2025)
  10. LND Finance Homepage (Accessed May 16, 2025)
  11. @Lnd_fi Twitter (Accessed May 16, 2025)
  12. @Lnd_fi Twitter (Accessed May 16, 2025)
  13. Tiancheng Mai - "LND @Lnd_fi recently experienced a security breach on 09/05/2025 resulting in the loss of $1.27M funds. (Accessed May 16, 2025)
  14. [The deployer 0x40c7...10c8 of LND swept all assets. Here is a postmortem I developed." - Twitter/X The deployer 0x40c7...10c8 of LND swept all assets. Here is a postmortem I developed." - Twitter/X] (Accessed May 16, 2025)
  15. Pool Admin Permissions Granted - SonicScan (Accessed May 16, 2025)
  16. LND Security Breach Post Mortem - LND Finance Medium (Accessed May 16, 2025)
  17. ZachXBT - "I helped initially attribute the incident to DPRK IT workers and flagged theft addresses but I am not formally engaged nor creating an investigative report for them." - Twitter/X (Accessed May 16, 2025)