DiviCube

The 11-Million Drain: A Post-Audit Protocol Exploit Two Months into a Truce

Technology | 0xHasu |

On May 10, 2026, a DeFi lending protocol on Arbitrum lost 11 million in a targeted exploit. The attack occurred exactly two months after the protocol signed a formal “truce” with a known hacker collective—a public agreement to cease hostilities in exchange for a bug bounty and a promise to patch all disclosed vulnerabilities. The timing is not coincidental. It is a pattern.

The protocol, which we will call “LendCircle” for anonymity, had been under active attack from a group that identified as “ChainFerret” since early 2025. After a series of small-scale exploits totaling 3 million, both parties agreed to a truce mediated by a third-party security firm. The terms were straightforward: ChainFerret would disclose all known vulnerabilities, LendCircle would pay a 500,000 bounty, and both sides would refrain from further action. The truce was announced on March 10, 2026. On May 10, 2026, a single transaction drained 11 million from LendCircle’s liquidity pool.

The data does not negotiate; it only reveals. The attack exploited a rounding precision flaw in the protocol’s fee calculation logic—a vulnerability that had been present in the codebase for 14 months, passed through three separate audits, and was never disclosed by ChainFerret during the truce negotiations. The transaction hash shows a clean, six-step execution: flash loan, swap, deposit, manipulate fee rounding, withdraw, repay. Total gas cost: 0.17 ETH. The attacker left a memo in the transaction: “Truce was for bugs we told you about. This one you should have found yourself.”

Context: The Truce Economy The concept of a “truce” in DeFi is rooted in the belief that adversarial white-hat negotiations can replace endless cat-and-mouse games. LendCircle’s decision was not unique. In 2025, at least six major protocols signed similar agreements with hacker groups after suffering repeated attacks. The logic is persuasive: stop the bleeding, buy time, patch the known holes. But the truce creates a false sense of security. Once the public announcement is made, the pressure on the protocol to maintain continuous vigilance drops. Auditors close their reviews. Developers shift focus to new features. The attacker, meanwhile, retains a reserve of undisclosed exploits—insurance against future negotiations or a final payout.

Based on my experience auditing over 40 DeFi protocols, I have seen this pattern repeat. In 2021, I analyzed a protocol that had signed a “non-aggression pact” with a white-hat group. The group disclosed 12 vulnerabilities but withheld three critical ones. The protocol’s team, believing they were safe, paused their bug bounty program. Two months later, the withheld exploits were used by a third party who had purchased them on a darknet forum. The result was a 7 million loss. The truce is not a security solution; it is a temporary cease-fire in a war that never ends.

The 11-Million Drain: A Post-Audit Protocol Exploit Two Months into a Truce

Core: A Systematic Teardown of the Exploit Let us examine the on-chain evidence. The attacker’s address (0x9f4e…b3a2) was funded from a Tornado Cash-like mixer on the same day. The attack began with a flash loan of 50 million USDC from Aave. The loan was used to swap into LendCircle’s native token, LCT, on a DEX. The attacker then deposited the LCT into LendCircle’s lending pool as collateral. The key move: the attacker manipulated the fee calculation by depositing and withdrawing repeatedly in a single block, exploiting the rounding error that caused the protocol to over-credit fees. Each cycle generated a small profit; after 47 cycles, the total profit was 11 million. The entire operation took 12 seconds.

The 11-Million Drain: A Post-Audit Protocol Exploit Two Months into a Truce

The rounding flaw was in the _calculateFee function in the smart contract, line 89. The formula used integer division without proper scaling: fee = amount * rate / 10000. When amount was small, the rounding error was negligible. But when amount was large and the operation repeated, the error accumulated. The three audits—by firms A, B, and C—all passed this function. Why? Because the test cases used amounts that did not trigger the edge case. The audits were thorough but not exhaustive. The attacker found a gap in the test coverage.

Contrarian: What the Bulls Got Right The bulls—those who defended LendCircle’s truce strategy—argue that the protocol saved millions by not fighting a prolonged war. They point out that the truce prevented an estimated 15-20 million in further losses from known bugs. They are correct. The truce was a rational decision under uncertainty. The flaw was not the truce itself, but the assumption that the truce covered all vulnerabilities. The protocol’s team failed to maintain a posture of constant vigilance after the agreement. They reduced their internal security review frequency from weekly to monthly. They stopped monitoring the attacker’s social media and on-chain activity. The attacker, meanwhile, quietly tested the exploit on a forked testnet for 30 days before executing.

The bulls also note that the 11 million loss was only 2% of LendCircle’s total value locked. The protocol survived. The attacker returned 3 million after a public outcry—a partial refund. The net loss was 8 million, which the protocol covered by issuing a governance token sale. The users were made whole. From a business continuity perspective, the outcome was acceptable. But the question is not whether the protocol survived; it is whether the trust in the truce model is now broken.

Takeaway: The Accountability Call The LendCircle incident is not an anomaly; it is a warning. The DeFi industry has adopted a dangerous habit of treating security as a fixed-cost event: pay for an audit, sign a truce, move on. Security is a continuous process, not a checkbox. The attacker’s memo—“This one you should have found yourself”—is a damning indictment of the industry’s over-reliance on third-party audits and truce agreements. The data shows that the exploit was preventable. The code was public. The vulnerability was mathematically simple. The only missing ingredient was the will to look.

The 11-Million Drain: A Post-Audit Protocol Exploit Two Months into a Truce

If the industry continues to treat security as a negotiation rather than a discipline, the next truce will be followed by a larger drain. The question is not if, but when. Data does not negotiate; it only reveals.

Market Prices

Coin Price 24h
BTC Bitcoin
$63,070.2 +0.07%
ETH Ethereum
$1,881 +0.08%
SOL Solana
$75.49 +0.47%
BNB BNB Chain
$606.1 -0.82%
XRP XRP Ledger
$1 +0.00%
DOGE Dogecoin
$0.0699 -0.13%
ADA Cardano
$0.1778 -0.61%
AVAX Avalanche
$6.34 -4.05%
DOT Polkadot
$0.7598 -1.32%
LINK Chainlink
$9.41 +1.16%

Fear & Greed

34

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,070.2
1
Ethereum ETH
$1,881
1
Solana SOL
$75.49
1
BNB Chain BNB
$606.1
1
XRP Ledger XRP
$1
1
Dogecoin DOGE
$0.0699
1
Cardano ADA
$0.1778
1
Avalanche AVAX
$6.34
1
Polkadot DOT
$0.7598
1
Chainlink LINK
$9.41

🐋 Whale Tracker

🔴
0x29f4...0a9f
5m ago
Out
21,082 BNB
🔴
0x0f8d...c5b3
1d ago
Out
4,772,318 DOGE
🟢
0x3970...6ad9
12h ago
In
13,473 SOL

💡 Smart Money

0xbdb4...fe84
Market Maker
+$1.2M
60%
0xec3c...4ae6
Arbitrage Bot
+$1.2M
61%
0x1469...54b7
Early Investor
+$4.9M
62%