OceanAltOceanAlt

Security incident · 2023-01-16

LendHub

According to the public DefiLlama incident dataset, LendHub (Heco) suffered a security incident on 2023-01-16, with about $6.0M reported lost.

Date2023-01-16
Reported loss$6.0M
ChainHeco
Target typeDeFi Protocol
Technique classToken & Share Accounting
TechniqueIncorrect Share Accounting
Bridge incidentNo
Within 2023#34 by loss that year, 0.4% of all reported losses that year

How this kind of attack works

The contract's bookkeeping was wrong, for example the conversion between shares and assets, so the attacker redeemed far more than they put in.

Would a pre-payment check have helped

Needs other controls

Accounting and share-math bugs are contract-layer problems for code audits.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents