financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
Jul 16, 2024 8:42 AM

The decentralized finance (DeFi) platform LI.FI protocol has suffered an exploit amounting to over $8 million.

Cyvers Alerts reported detecting suspicious transactions within the LI.FI cross-chain transaction aggregator.

LI.FI Issues Warning After $8 Million Exploit

LI.FI confirmed the breach in a statement on July 16 via X: Please do not interact with any http://LI.FI powered applications for now! Were investigating a potential exploit. The team clarified that users who did not set infinite approval are not at risk, emphasizing that only those who manually set infinite approvals seem to be affected.

Please do not interact with any https://t.co/nlZEnqOyQz powered applications for now!

Were investigating a potential exploit. If you did not set infinite approval, you are not at risk.

Only users that have manually set infinite approvals seem to be affected.

Revoke all…

According to Cyvers Alerts, more than $8 million in user funds have been stolen, with the majority being stablecoins. According to on-chain data, the hackers wallet holds 1,715 Ether (ETH) valued at $5.8 million and USDC, USDT, and DAI stablecoins.

ALERT@lifiprotocol, Our system has raised suspicious transactions involving your https://t.co/3LzbDK99Ed

We recommend users to revoke their approvals for: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae

More than $8M have been drained so far from users and mostly stablecoins!… pic.twitter.com/zsj9DZWnpU

Cyvers Alerts advised users to revoke relevant authorizations immediately, noting that the attacker is actively converting USDC and USDT into ETH.

Crypto security firm Decurity provided insights into the exploit, stating that it involves the LI.FI bridge. The root cause is a possibility of an arbitrary call with user-controlled data via depositToGasZipERC20() in GasZipFacet, which was deployed 5 days ago, Decurity explained on X.

In general, the risks behind routers, cross-chain swaps, etc. are about token approvals. Raw native assets like (unwrapped) ETH are safe from these kinds of hacks b/c they dont have approvals as an option. Most users wallets also no longer do infinite approvals which gives a smart contract total control on removing any amount of their tokens. Its important to understand which tokens youre approving to which contracts.

This dashboard looks for all transactions of a user that intersects Lifi. Not all of these transactions indicate risk- but you can see how, broadly, integrations layers of tech (like how Metamask bridge uses Lifi on BSC) can complicate how users do or dont put their assets at risk. Revoke Cash is the most well known approval manager app.

But its also good security practice to simply rotate your address. New addresses start with 0 approvals, so starting fresh by moving your tokens to a fresh address is another good security practice. commented Carlos Mercado, Data Scientist at Flipside Crypto.

Recent Exploit Mirrors March 2022 Attack

Further analysis by PeckShield alert revealed that the vulnerability is similar to a previous attack on LI.FIs protocol that occurred on March 20, 2022. That incident saw a bad actor exploit LI.FI’s smart contract, specifically the swapping feature, before bridging.

The attacker manipulated the system to call token contracts directly within their contract’s context, making users who had given infinite approval vulnerable. This exploit resulted in the theft of approximately 205 ETH from 29 wallets, affecting tokens such as USDC, MATIC, RPL, GNO, USDT, MVI, AUDIO, AAVE, JRT, and DAI.

The bug is basically the same. Are we learning anything from the past lesson(s)? PeckShield Alert said in a July 16 X post.

Following the 2022 incident, LI.FI disabled all swap methods in its smart contract and worked on developing a fix to prevent future vulnerabilities. However, the recurrence of a similar exploit raises concerns about the platforms security measures and whether adequate steps were taken to address the vulnerabilities identified in the previous breach.

LI.FI is a liquidity aggregation protocol that allows users to trade across various blockchains, venues, and bridges.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
BTC Price Recovers After Monthly Lows Despite Continuous Bitcoin ETF Outflows
BTC Price Recovers After Monthly Lows Despite Continuous Bitcoin ETF Outflows
Jun 19, 2024
The spot Bitcoin ETFs in the States have reversed the late May/early June trend and have seen several consecutive days of outflows, worth more than $600 million. These adverse developments on the ETF front have impacted the price of the underlying asset, as well as the entire crypto market, and BTC slumped to a monthly low before it bounced off...
Bitcoin Retail Crowd Still Missing, Can They Push BTC Above $70K?
Bitcoin Retail Crowd Still Missing, Can They Push BTC Above $70K?
Jun 18, 2024
Bitcoins price has been trapped within a range below $70,000 for quite some time now. Attempts to surpass this level have been brief and unsuccessful as the digital asset failed to maintain the upward momentum. Interestingly, new research revealed that the retail crowd is not here yet. Bitcoin Retail Crowd Not Here Yet According to CryptoQuants latest analysis, the current...
LDO, ENS, and Other Ethereum
LDO, ENS, and Other Ethereum
Jun 19, 2024
Bitcoins price actions were quite painful yesterday as the asset dumped twice to a monthly low of $64,000 before it managed to recover some ground. Several altcoins have bounced off following yesterdays market-wide crash, especially those with some sort of connection to the Ethereum ecosystem. ETH, ENS, LDO on the Rebound Perhaps the biggest news in the crypto industry today...
Brett (BRETT) Flips Bonk Inu (BONK) After a 15% Daily Surge: Details
Brett (BRETT) Flips Bonk Inu (BONK) After a 15% Daily Surge: Details
Jun 19, 2024
TL;DR The cryptocurrency market has rebounded, with major coins like Ethereum, Solana, and Cardano seeing gains. The frog-themed meme coin Brett (BRETT) surged over 15%, fueled by new exchange listings, and now ranks as the sixth-largest in its category. Climbing the Crypto Ladder The cryptocurrency sector has recovered much of the losses witnessed in the past few days, with its...
Copyright 2023-2025 - www.financetom.com All Rights Reserved