LND hack — May 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 9, 2025 |
| Target type | Lending protocol |
| Loss | $1,270,000Published estimates range $1,180,000 to $1,420,000Price at time of incident |
| Method | Insider actionA developer with control of the protocol's deployment address published modified AToken and VariableDebtToken contracts in which the onlyPool access-control modifier was rewritten to also accept any address holding the Pool Admin role. The deployer held that role and called transferUnderlyingTo to sweep the pooled assets. |
| Chains | Other |
| Attributed to | Developer hired by LND, described in LND's post-mortem as an undercover DPRK (North Korean) IT workerSuspected |
| Outcome | Unresolved |
What happened
LND (LND.fi), an Aave fork deployed on the Sonic network, was drained on 9 May 2025. The protocol's own post-mortem puts the loss at approximately $1.27 million and says the funds were taken by a developer the team had hired, whom it describes as an undercover North Korean IT worker. The mechanism was a backdoor placed in the protocol's own contracts rather than an external intrusion. The deployer published modified AToken and VariableDebtToken contracts in which the onlyPool access-control modifier was rewritten so that any address holding the Pool Admin role, not only the Pool contract itself, could call functions reserved for the pool. The deployer held that role. At 02:29:09 UTC the deployer address began calling transferUnderlyingTo and moved the pooled assets out. The altered contracts had been live and publicly visible on-chain for weeks before they were used. Proceeds were bridged off Sonic and split across wallets on BNB Chain, Ethereum and Hyperliquid, with part deposited to exchanges. The figures differ. LND's post-mortem states approximately $1.27 million. An independent analysis by Tiancheng Mai, published before LND's own account, first gave $1.27 million and was later revised to about $1.42 million on the basis of a wallet-by-wallet trace. Security firm Halborn described the loss as $1.18 million. LND paused the protocol, revoked the compromised account's privileges, said it had reported the theft to law enforcement and exchanges, and offered a 15% white-hat bounty for the return of funds. No charges or formal government attribution to North Korea have been published.
Law enforcement
LND states in its post-mortem that it filed reports with law enforcement and with centralised exchanges, and that ZachXBT and SEAL were tracking the funds. No public case, charges or government attribution have been identified.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xc0454e29835479ee80d6f42965a16dcee9bfd868
Sources
- LND (LND.fi)Primary · retrieved 2026-08-01
- Tiancheng Mai (HackMD)Secondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@lndfi/lnd-security-breach-post-mortem-2c54ac006050
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "LND hack — May 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/lndhttps://itokenly.com/hacks/lndPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.