financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
Jul 16, 2024 8:42 AM

The decentralized finance (DeFi) platform LI.FI protocol has suffered an exploit amounting to over $8 million.

Cyvers Alerts reported detecting suspicious transactions within the LI.FI cross-chain transaction aggregator.

LI.FI Issues Warning After $8 Million Exploit

LI.FI confirmed the breach in a statement on July 16 via X: Please do not interact with any http://LI.FI powered applications for now! Were investigating a potential exploit. The team clarified that users who did not set infinite approval are not at risk, emphasizing that only those who manually set infinite approvals seem to be affected.

Please do not interact with any https://t.co/nlZEnqOyQz powered applications for now!

Were investigating a potential exploit. If you did not set infinite approval, you are not at risk.

Only users that have manually set infinite approvals seem to be affected.

Revoke all…

According to Cyvers Alerts, more than $8 million in user funds have been stolen, with the majority being stablecoins. According to on-chain data, the hackers wallet holds 1,715 Ether (ETH) valued at $5.8 million and USDC, USDT, and DAI stablecoins.

ALERT@lifiprotocol, Our system has raised suspicious transactions involving your https://t.co/3LzbDK99Ed

We recommend users to revoke their approvals for: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae

More than $8M have been drained so far from users and mostly stablecoins!… pic.twitter.com/zsj9DZWnpU

Cyvers Alerts advised users to revoke relevant authorizations immediately, noting that the attacker is actively converting USDC and USDT into ETH.

Crypto security firm Decurity provided insights into the exploit, stating that it involves the LI.FI bridge. The root cause is a possibility of an arbitrary call with user-controlled data via depositToGasZipERC20() in GasZipFacet, which was deployed 5 days ago, Decurity explained on X.

In general, the risks behind routers, cross-chain swaps, etc. are about token approvals. Raw native assets like (unwrapped) ETH are safe from these kinds of hacks b/c they dont have approvals as an option. Most users wallets also no longer do infinite approvals which gives a smart contract total control on removing any amount of their tokens. Its important to understand which tokens youre approving to which contracts.

This dashboard looks for all transactions of a user that intersects Lifi. Not all of these transactions indicate risk- but you can see how, broadly, integrations layers of tech (like how Metamask bridge uses Lifi on BSC) can complicate how users do or dont put their assets at risk. Revoke Cash is the most well known approval manager app.

But its also good security practice to simply rotate your address. New addresses start with 0 approvals, so starting fresh by moving your tokens to a fresh address is another good security practice. commented Carlos Mercado, Data Scientist at Flipside Crypto.

Recent Exploit Mirrors March 2022 Attack

Further analysis by PeckShield alert revealed that the vulnerability is similar to a previous attack on LI.FIs protocol that occurred on March 20, 2022. That incident saw a bad actor exploit LI.FI’s smart contract, specifically the swapping feature, before bridging.

The attacker manipulated the system to call token contracts directly within their contract’s context, making users who had given infinite approval vulnerable. This exploit resulted in the theft of approximately 205 ETH from 29 wallets, affecting tokens such as USDC, MATIC, RPL, GNO, USDT, MVI, AUDIO, AAVE, JRT, and DAI.

The bug is basically the same. Are we learning anything from the past lesson(s)? PeckShield Alert said in a July 16 X post.

Following the 2022 incident, LI.FI disabled all swap methods in its smart contract and worked on developing a fix to prevent future vulnerabilities. However, the recurrence of a similar exploit raises concerns about the platforms security measures and whether adequate steps were taken to address the vulnerabilities identified in the previous breach.

LI.FI is a liquidity aggregation protocol that allows users to trade across various blockchains, venues, and bridges.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Bitcoin ETFs Saw $300 Million in Daily Net Inflows, No Outflows Recorded
Bitcoin ETFs Saw $300 Million in Daily Net Inflows, No Outflows Recorded
Jul 16, 2024
The US spot Bitcoin ETFs recorded a daily net inflow of $301 million on July 15th. This extended their winning streak to seven consecutive days amidst a broader market recovery. None of the ETFs recorded outflows for the day. Bitcoin ETFs Rake in $16.11B in Net Inflows Since Jan According to the data compiled by SoSoValue, BlackRocks IBIT, the top...
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
LI.FI DeFi Platform Exploited, Over $8 Million Lost to Attack
Jul 16, 2024
The decentralized finance (DeFi) platform LI.FI protocol has suffered an exploit amounting to over $8 million. Cyvers Alerts reported detecting suspicious transactions within the LI.FI cross-chain transaction aggregator. LI.FI Issues Warning After $8 Million Exploit LI.FI confirmed the breach in a statement on July 16 via X: Please do not interact with any http://LI.FI powered applications for now! Were investigating...
Gold (XAU/USD)
Gold (XAU/USD)
Jul 16, 2024
Gold (XAU/USD) - Latest Sentiment Analysis US rate cut fully priced in on September 18.Gold’s multi-month range now in danger. Recommended by Nick Cawley Get Your Free Gold Forecast The price of gold continues to push higher and is set to test the May 20th all-time high of $2,450/oz. Renewed speculation that the Federal Reserve will cut rates by 25...
Kraken to Begin Distributing Mt. Gox Compensation Funds Soon: $3.1B Worth Bitcoin Transfer Noted
Kraken to Begin Distributing Mt. Gox Compensation Funds Soon: $3.1B Worth Bitcoin Transfer Noted
Jul 16, 2024
Kraken has announced the receipt of funds from the Mt. Gox Rehabilitation Trustees on July 16th. This marks a significant step towards compensating those impacted by the historic collapse of the Mt. Gox exchange a decade ago. In an email to the affected parties, the exchange said it plans to begin distributing Bitcoin (BTC) and Bitcoin Cash (BCH) to affected users...
Copyright 2023-2026 - www.financetom.com All Rights Reserved