Likwid Exploited for $55,721 Due to Contract Bug
The BNB Chain DeFi protocol Likwid suffered an exploit resulting in a loss of $55,721. The incident involved a bug in the margin-borrow contract that allowed the attacker to drain funds from the vault.
The BNB Chain DeFi protocol Likwid was exploited due to a bug in its margin-borrow contract. Specifically, in the leverage=0 path of LikwidMarginPosition, the pair reserves were not updated, allowing the attacker to reuse the same quote for each borrow. This vulnerability was exploited after the attacker pumped a thin meme pool, enabling them to repeatedly cycle through collateral and borrow, ultimately draining 74.31 BNB from the vault.
The total loss from this exploit amounted to approximately $55,721. Following the attack, the stolen funds were sent to Tornado Cash, a service known for providing privacy through transaction obfuscation. This action complicates the tracing of the funds, as Tornado Cash is designed to mix transactions, making it harder to link the stolen assets back to the original exploit.
The incident highlights a specific technical flaw within Likwid's contract that was leveraged to execute the attack. The use of the BNB Chain for this exploit means that the transaction records are available on-chain, but the obfuscation provided by Tornado Cash may hinder recovery efforts.
