ChainBleedv0.1 · open intel
← back to feed·TOKEN-SUPPLY2026-04-16 · 1mo ago
Incident · SLOWMIST

Rhea Lend

Contract Vulnerability
Estimated loss
$18.40M
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
TOKEN SUPPLY
TOKEN-SUPPLYBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2026-03/Curve_LlamaLend_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

On April 16, 2026, Rhea Finance (formerly Burrow Finance) was exploited. The attacker spent two days preparing with 423 wallets, deploying fake token contracts, and creating manipulated liquidity pools on Ref Finance to build fake swap routes. They then exploited a logic flaw in Rhea Lend’s margin trading slippage protection (which incorrectly summed min_amount_out without accounting for reused intermediate tokens in multi-step swaps), allowing them to borrow real assets, trigger forced liquidations, and drain the reserve pool. Initial estimates were ~$7.6M, later revised to $18.4M total drained. The attack primarily affected the Rhea Lend contract (Rhea DEX was paused precautionarily). The team paused contracts, collaborated with Tether to freeze assets, and the attacker returned portions of funds. The protocol committed to covering any remaining shortfall, ensuring user funds were protected. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 18,400,000.

Primary source
https://rekt.news/rhea-finance-rekt
Sourced from
slowmist
Technical record
chain
protocol
Rhea Lend
bug_class
token-supply
date_occurred
2026-04-16
loss_usd
$18,400,000
source_id
sm:rhea-lend::2026-04-16
Related — same bug class· token-supply
2026-02-23
3mo ago
BASE
DGLD
Infinite Mint and Dump
token-supply
UNRATED
2026-01-22
4mo ago
SAGA
SagaEVM (Saga chainlet)
SagaEVM — Ethermint IBC message validation bypass → unlimited stablecoin mint
token-supply
$7.00M
AUDIT-CATCHABLE
2026-01-21
4mo ago
SAGA
Saga
Infinite Mint and Dump
token-supply
$7.00M
UNRATED
2025-11-23
6mo ago
BSC
Port3 Network
Infinite Mint and Dump
token-supply
$166.0K
UNRATED
2025-09-23
8mo ago
MULTI
Seedify
Infinite Mint and Dump
token-supply
$1.00M
UNRATED
2025-08-26
9mo ago
PULSEC
BetterBank
Infinite Mint and Dump
token-supply
$5.00M
UNRATED
ChainBleed — live web3 threat intelligence