USENIX Security2026Top-tier venue
Liquidity Mining as an Attack Surface: Incentive-Induced Liquidity Attacks in Concentrated Liquidity Market Makers
Nora Sinong Lu, Chon Kit Lao, Yunlong Mao, Xiaobo Zhou, Ruizhe Jia, Kanye Ye Wang
Abstract
Decentralized finance (DeFi) platforms commonly deploy volume-based incentive programs to bootstrap liquidity and improve market efficiency. We show that such subsidies, while well-intentioned, can create an underexplored economic attack surface in concentrated liquidity market makers (CLMMs). These subsidies enable a novel manipulation strategy. Attackers attract subsidized trading volume by providing highly concentrated liquidity, artificially inflating yields and luring victim liquidity providers into narrow price ranges. Once sufficient victim liquidity has accumulated, the attacker induces a price crash to extract value. We formalize this behavior as an incentive-induced liquidity attack and prove that it arises endogenously whenever subsidy intensity and volume caps exceed critical thresholds. Although subsidies are intended to bootstrap liquidity, these attacks ultimately lead to substantial liquidity depletion, causing platforms to incur incentive costs while market liquidity deteriorates. We conduct a large-scale measurement study on incentivized CLMM pools on BSC that are tied to Binance Alpha programs. We identify 29 attack events across 18 pools with 99 positive-loss victim addresses across 13 loss-bearing episodes and $2.87M in measured victim loss. These measurements show that incentive programs can amplify manipulation by introducing externalities that enable new extraction opportunities. Based on our findings, we propose mitigation strategies that reshape incentive parameters and information disclosure to reduce liquidity-provider exposure to incentive-induced attacks. Our findings show that incentive mechanisms designed to improve market quality can instead create the security vulnerabilities they aim to prevent.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a13b3ecf-e20e-4592-bf7f-fdcf0df75fd7Builds on16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le et al.S&P 2021 · 243 citations
- Frontrunner Jones and the Raiders of the Dark Forest: An Empirical Study of Frontrunning on the Ethereum BlockchainChristof Ferreira Torres, Ramiro Camino, Radu StateUSENIX Security 2021 · 179 citations
- The Anatomy of a Cryptocurrency Pump-and-Dump SchemeJiahua Xu, Benjamin LivshitsUSENIX Security 2019 · 146 citations
Related papers
- DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsMaoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang et al.ISSTA 2024 · 9 citations
- Following Devils' Footprint: Towards Real-time Detection of Price Manipulation AttacksBosi Zhang, Ningyu He, Xiaohui Hu, Kai Ma et al.USENIX Security 2025
- Serial Scammers and Attack of the Clones: How Scammers Coordinate Multiple Rug Pulls on Decentralized ExchangesPhuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak et al.WWW 2025 · 6 citations
- I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and CountermeasuresMingyi Liu, Jun Ho Huh, HyungSeok Han, Jaehyuk Lee et al.USENIX Security 2024 · 6 citations
- On the Just-In-Time Discovery of Profit-Generating Transactions in DeFi ProtocolsLiyi Zhou, Kaihua Qin, Antoine Cully, Benjamin Livshits et al.S&P 2021 · 148 citations
