LendHub hack — January 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 13, 2023 |
| Target type | Lending protocol |
| Loss | $6,000,000Price at time of incident |
| Method | Contract logic errorAn incomplete migration left a deprecated IBSV cToken market live alongside its replacement, both pricing the same underlying asset identically under separate Comptroller contracts. The attacker minted and redeemed in the retired market while borrowing against the same collateral in the new market; because each Comptroller accounted for the position independently, liabilities were understated and the new market could be drained. |
| Chains | Other |
| Outcome | Unresolved |
What happened
LendHub, a multi-chain lending protocol operating on Huobi Eco Chain (HECO) and BNB Chain, lost about $6 million on 12 January 2023. The protocol announced the loss the following day and later contacted security firms and exchanges to help track the funds.
The cause was an incomplete migration rather than a smart-contract bug. LendHub had replaced its IBSV market with a new version governed by its own Comptroller, but never removed the retired IBSV cToken. Both markets stayed live and both priced the same underlying asset identically. SlowMist, which first flagged the incident, described the attacker manipulating the minting and redeeming process in the old market while borrowing in the new one; because the two Comptrollers accounted for the same collateral independently, the borrower's liabilities were understated and the new market could be emptied.
Preparation was visible on-chain. CertiK traced the exploiter receiving 100 ETH from Tornado Cash on Ethereum at 10:11 PM UTC on 11 January, swapping into HT and USDT, and bridging to HECO before the attack. Afterwards the proceeds left HECO through Transit Swap and Multichain for Ethereum and Optimism. CertiK put the total under the attacker's control at $5,373,679.79: around $2.7 million in DAI and USDT on Ethereum, approximately $1 million in WBTC on Optimism, and 1,100 ETH - about $1.5 million - sent to Tornado Cash. The Block reported around $2.6 million in USDT and DAI still sitting in the attacker's wallet at the time of writing.
Nothing was recovered and no one has been identified. The $6 million headline figure and CertiK's $5.37 million are not competing totals: the latter is the portion successfully traced.
Sources
- CertiKSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://certik.com/resources/blog/1IDWJfEBm6GK5sIIdfhfQn-lendhub-incident-analysis
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "LendHub hack — January 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/lendhubhttps://itokenly.com/hacks/lendhubPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.