All findings

lemon.fun ·Robinhood Chain

LemonCurveFactory legacy bonding curve — total buyer-fund theft

Critical

Verified with working PoC

Contract: 0xb5B70EF8698e022d38E2AC211ddfd0a5436bD1Ad

access controltrust parameterfund theft

Summary

LemonCurveFactory.launch() accepts caller-supplied dexFactory/positionManager addresses with no validation against canonical DEX addresses. At graduation, the bonding curve approves the attacker-chosen positionManager for all real buyer ETH and calls mint() on it.

Root cause

Missing validation of deployment-time trust parameters lets a malicious deployer walk away with 100% of raised funds while buyers hold worthless tokens - no real liquidity pool is ever created.

Verification

PoC ran against the real, live, verified LemonCurveFactory on Robinhood Chain mainnet via a forge fork test and confirmed the theft end to end.

Verified against real, live deployed contract state.

Receipt on GitHub