According to the intelligence of SlowMist Security Zone, LendHub, the Heco ecological cross-chain lending platform, was attacked and caused a loss of nearly 6 million US dollars. The reason for this attack is that there are two lBSV cTokens in LendHub, one of which has been abandoned in April 2021 but has not been removed from the market, which resulted in both the old and new lBSV existing in the market. Moreover, the Comptrollers corresponding to the old and new lBSV are not the same, but both have prices in the market, which results in a split in the calculation of liabilities in the old and new markets. Attackers take advantage of this problem to redeem mortgages in the old market and carry out lending operations in the new market, maliciously extorting protocol funds in the new market. At present, the main profit address for hackers is 0x9d01..ab03, and the source of the hacker attack fee is the 100 ETH received from Tornado Cash on January 12. As of this point, the hacker has transferred 1,100 ETH to Tornado Cash in 11 transactions. At present, SlowMist has passed through the threat intelligence network and obtained some traces of hackers.