Refreshed 4h ago· updates every 6h

dForce / Lendf.Me (2020) — Crypto Hack

Fully Recovered
Apr 19, 2020·
Ethereum
Amount Stolen
$25.0M
~$25M in ERC-777 tokens and ETH
Recovered
$25.0M
100% of stolen funds

Lendf.Me lending protocol was drained via ERC-777 reentrancy attack, exploiting the token callback mechanism to repeatedly borrow against the same collateral.

Summary

Lendf.Me lending protocol was drained via ERC-777 reentrancy attack, exploiting the token callback mechanism to repeatedly borrow against the same collateral.

How It Was Compromised — DeFi via Reentrancy

DeFiReentrancy

The attacker exploited an ERC-777 token callback reentrancy vulnerability in Lendf.Me (dForce's lending protocol). By depositing imBTC (an ERC-777 token), the attacker triggered the token's callback during deposit to reenter the withdraw function, effectively borrowing against the same collateral repeatedly and draining all protocol assets across multiple tokens.

Fund Flow & Laundering Analysis

Unusually, the attacker returned all funds within 4 days after being identified through KYC information at dYdX and IP address metadata they left on-chain. dForce negotiated fund return in exchange for a bounty. Protocol resumed operations. This is one of the few 2020 DeFi hacks where nearly all funds were recovered.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.