Bug in Solana Token Lending Contract Fixed, More Than $2 Billion Made Exploitable
A bug in the token lending contract of the Solana Program Library (SPL) was recently found and fixed by Neodyme, a security auditing firm. The bug, that was discovered a couple of months back, could have affected several...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
A bug in the token lending contract of the Solana Program Library (SPL) was recently found and fixed by Neodyme, a security auditing firm. The bug, that was discovered a couple of months back, could have affected several decentralized finance protocols holding more than $2 billion in total value locked (TVL). Their team identified the possible protocols using this contract (or derivatives of it) and disclosed the bug immediately.
Solana SPL Rounding Bug Puts Funds at RiskA bug in one of the token lending contracts that is part of Solana’s Program Library (SPL), a group of on-chain programs targeting the Sealevel parallel runtime on Solana, put the funds of several protocols at risk. Neodyme, a security agency, had disclosed this vulnerability months ago and alerted about it, but the bug, due to its apparently innocuous effect, had not been resolved.
The bug caused a rounding error that delivers more tokens than the ones being deposited by the users to the contract. However, the bug was not exploitable without an organized attack that targeted the vulnerability directly. Neodyme, the auditing group, managed to reproduce it and create a script that took advantage of it.
Importance of Open SourceMore than $2 billion in several tokens on these protocols were at risk of being drained slowly by taking advantage of this exploit. More so, if the attack had been conducted in a smart way, it wouldn’t have triggered any alarms, and would just be detected as a slow drain of APY in some pools. Neodyme remarked about the importance of open source code for auditors to be involved and help correct these kinds of bugs. It stated:
We believe the most secure code is open-source, and as auditors we believe one of the best ways to write better code is to understand vulnerabilities.
After discovering this exploit, Neodyme shared its existence with teams that would probably be using the program as a tool for their operations. Among these were some protocols that are not open source on the Solana chain, and cannot be directly verified by their users. This made it difficult for them to directly verify whether these platforms were exploitable by the bug. However, they communicated with the teams behind these protocols, who are in charge of fixing the issue individually.
The SPL token-lending contract had already been reviewed before, and two projects using it have also been audited independently: Solend by Kudelski and Larix by Slowmist.
What do you think about the exploit corrected in the Solana token lending contract? Tell us in the comments section below.
Why this matters
This altcoin story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Bitcoin NewsRelated market context
AI Predicts Solana Price at the End of 2026
Solana (SOL) is trading around $95 as of late August 2026, roughly a third of its January 2025 all-time high near $296. After a br...
Kylie Jenner’s X account posts and deletes compromised Solana token address
The incident highlights the vulnerability of celebrity accounts to exploitation, impacting market dynamics and investor trust in d...
Coinbase Put Nvidia and Apple Stock Onchain: But Does Weekend Trading Create Liquidation Risk?
Coinbase tokenized US equities went live on Base on Monday, putting four technology stocks onchain as transferable tokens that eli...
Bitcoin Price Prediction: BTC Broke $80,000 for First Time in 15 Weeks
Bitcoin just punched through $80,000 for the first time in almost 15 weeks. This is very bullish for Bitcoin price prediction, and...
Bitcoin Wakes Up as Treasury Blinks: Is the Great Catch-Up Trade Finally Here?
The speed of the move caught a heavily bearish market off guard. More than $4 billion in short crypto positions were liquidated, c...
Fidelity grants ETFs power to stake 100% of crypto while outlining exit delay risks
Fidelity’s FETH and FSOL staking plans give its Ethereum and Solana exchange-traded products authority to stake up to 100% of thei...