Menu
Browse

Lendf.me

Primary URL Location Industry
lendf[.]me
Country China
Financial Services Icon
Financial Services
Profile

Lendf.me operates as a decentralized finance platform that enables users to lend and borrow digital assets through smart contracts on the Ethereum blockchain. The platform supports ERC‑777 standard tokens, as evidenced by the exploit that targeted this token interface during the April 2020 incident. It also accommodates imBTC, an Ethereum‑based representation of Bitcoin, allowing users to use tokenized Bitcoin as collateral or for lending activities. By integrating with protocols such as Uniswap, Lendf.me provides liquidity pathways for its users to swap assets while maintaining lending positions. Its services are accessible to a global user base, with the project’s headquarters located in China.

Lendf.me gained notoriety in April 2020 when attackers executed a reentrancy vulnerability exploit that drained approximately $25 million from the platform’s reserves. The attack leveraged a known flaw in the ERC‑777 token standard that had been previously documented by OpenZeppelin, underscoring the platform’s exposure to widely recognized smart‑contract risks. Following the exploit, both Lendf.me and associated protocols were temporarily taken offline, and imBTC transactions were suspended to prevent further losses. Through blockchain‑based communication, the attackers returned virtually all of the stolen funds—about $23.8 million—after inadvertently revealing their IP address, with only minor discrepancies remaining due to cryptocurrency price fluctuations. This incident highlighted Lendf.me’s substantial capital deployment prior to the breach and its integration within the broader DeFi ecosystem. The episode also demonstrated an atypical negotiation‑driven recovery process that is uncommon in typical cryptocurrency hacks.

Incidents
Linked incidents available to members
1 incident