lemon.fun ·Robinhood Chain
LemonCurveFactory legacy bonding curve — total buyer-fund theft
Verified with working PoC
Contract: 0xb5B70EF8698e022d38E2AC211ddfd0a5436bD1Ad
Summary
LemonCurveFactory.launch() accepts caller-supplied dexFactory/positionManager addresses with no validation against canonical DEX addresses. At graduation, the bonding curve approves the attacker-chosen positionManager for all real buyer ETH and calls mint() on it.
Root cause
Missing validation of deployment-time trust parameters lets a malicious deployer walk away with 100% of raised funds while buyers hold worthless tokens - no real liquidity pool is ever created.
Verification
PoC ran against the real, live, verified LemonCurveFactory on Robinhood Chain mainnet via a forge fork test and confirmed the theft end to end.
Verified against real, live deployed contract state.
Receipt on GitHub