Lendf.Me, the lending protocol within the dForce network, was drained of approximately $25 million in cryptoassets on April 19, 2020 after an attacker exploited the interaction between its smart contracts and imBTC, a token compatible with Ethereum’s ERC-777 standard.

DForce subsequently confirmed the date and approximate value of the assets removed. SlowMist, which participated in the incident response, calculated an event-day loss of about $24.7 million across wrapped ether, tokenized bitcoin and several stablecoins. The difference between that estimate and the rounded $25 million figure reflects valuation methodology and changing token prices, not a separately identified loss.

The attack disabled a substantial lending venue and turned a contract-level programming weakness into a test of whether decentralized-finance systems could contain failures without a bank, clearinghouse or conventional account-reversal process.

How the contracts were exploited

The available technical record identifies the incident as a reentrancy attack involving imBTC. ERC-777-compatible tokens can invoke callback functions while a transfer is being processed. That capability is not inherently an exploit, but contracts integrating such tokens must prevent an external callback from re-entering sensitive functions before internal balances have been finalized.

According to dForce and SlowMist, the attacker used the callback path to re-enter Lendf.Me’s supply function during withdrawals. The protocol could therefore recognize an inflated imBTC supply balance before completing its accounting update. That apparent collateral was then used to borrow other assets from Lendf.Me’s pooled markets.

Ethereum records associate the activity with an address later labeled by Etherscan as “Lendf.Me Hacker 1” and an attack contract identified by security investigators. Those records verify transfers and contract interactions, but the blockchain alone does not establish the operator’s identity or intent.

An abrupt collapse in recorded liquidity

The Block reported on April 19, 2020 that DeFi Pulse’s dForce dashboard showed total value locked falling from $24.9 million during the preceding 24-hour period to $6 at the report’s observation time. That dashboard reading indicated that nearly all tracked liquidity had left the system, although total value locked was a third-party, price-sensitive estimate rather than an audited statement of customer losses.

The institutional timing amplified the impact. On April 15, 2020, dForce had announced a $1.5 million strategic financing led by Multicoin Capital, with participation from Huobi Capital and CMB International. Multicoin described Lendf.Me as having accumulated roughly $20 million of collateral within a few months. Four days later, the exploit demonstrated that capital formation and rapid liquidity growth did not substitute for secure integration testing.

The incident also followed an imBTC-related reentrancy exploit against a Uniswap liquidity pool on April 18, 2020. By April 19, the relevant risk was therefore not purely theoretical: callback-enabled token behavior had been used against two separate financial contracts on consecutive dates.

What was known on April 19

DForce said it paused Lendf.Me and USDx contracts, closed the website for investigation, contacted security teams, exchanges and law-enforcement agencies, and sought to monitor or restrict the attacker’s addresses. Contemporaneous reports also said the attacker had contacted the project and that discussions were contemplated.

As of the April 19 event-day record, however, recovery was uncertain. No verified information available that date established that users would be repaid, that the attacker had been identified or that the removed assets would be returned.

Later context

This outcome was not knowable on April 19: dForce reported on April 21 that nearly all of the assets had been recovered, then published a redistribution plan on April 26. Those later developments clarify the incident’s resolution but do not change the event-day fact that the lending contracts had been compromised and approximately $25 million had been removed.

Primary sourcedForce — Lendf.Me Hack Resolution Part I: Asset Redistribution Plan, April 26, 2020

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.