Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
LI.FI loses estimated $9 million in exploit

LI.FI loses estimated $9 million in exploit

The Block2024/07/16 14:34
By: The Block
W+0.80%ETH+0.39%
Quick Take Cross-chain blockchain protocol LI.FI has lost around $9 million in an exploit, security firms say. The team has asked users to avoid the protocol and revoke permissions. Security firm Peckshield alleges a similar attack affected LI.FI in 2022.

Cross-chain blockchain protocol LI.FI has been exploited, the team said on the social media platform X. The team is investigating the possible hack, which appears to only affect users who manually set certain features.

"Please do not interact with any LI.FI powered applications for now," the LI.FI team wrote. "We're investigating a potential exploit. If you did not set infinite approval, you are not at risk."

“[W]e urge all users to immediately use our secluded revoke website,” LI.FI wrote, adding that “4 more security breaches have been identified.” 

Individuals can check to see if they may be implicated by visiting scan.li.fi and can revoke permissions via revoke.cash.

Security firm Decurity said the “root cause” appears to be “an arbitrary call with user controlled data” to a gas contract deployed five days ago to pay blockchain fees on Ethereum ETH +1.23% .

“The hacker crafted special calldata with transferFrom() calls and passed it as swapData to depositToGasZipERC20 to steal approved tokens from the bridge,” Decurity researchers wrote on X. 

The attack appears to be a version of the “call injection” exploit that allows attackers to use parameters in the original code to execute legitimate, but unexpected transactions. This type of vulnerability reportedly caused hundreds of millions of dollars worth of crypto to be lost.

A wallet containing drained funds controls over $4 million in ETH and nearly $200,000 in DAI stablecoins, according to DeFi World data . However, that amount is likely an understatement, as USDT and USDC stablecoins also appear to be leaving the platform. Security firm Certik estimates the total losses at around $9 million.

Peckshield , another security firm, alleges a similar attack hit LI.FI in 2022.


Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

MegaETH Valuation Game: A Good Entry Opportunity or Approaching Risk?

The L2 project MegaETH, backed by Vitalik, is about to launch its public sale.

Chaincatcher2025/10/17 04:52
BitMine Adds $417 Million in Ethereum Amid Market Dip

Quick Take Summary is AI generated, newsroom reviewed. BitMine purchased 104,336 ETH worth $417 million during a 20% price dip. Rising Ethereum whale activity signals renewed institutional accumulation. On-chain data confirms large holders are steadily increasing their positions. The move highlights confidence in Ethereum’s long-term strength despite short-term volatility.References 🔥 TODAY: BitMine bought 104,336 $ETH worth $417M as prices fell 20% from August highs, per onchain data.

coinfomania2025/10/17 04:06

Trending news

More
1
MegaETH Valuation Game: A Good Entry Opportunity or Approaching Risk?
2
The Manipulation Logic and Survival Strategies Behind the "Largest Liquidation in History"

Crypto prices

More
Bitcoin
Bitcoin
BTC
$108,838.3
-2.04%
Ethereum
Ethereum
ETH
$3,913.92
-2.36%
Tether USDt
Tether USDt
USDT
$1
-0.04%
BNB
BNB
BNB
$1,145.11
-2.89%
XRP
XRP
XRP
$2.35
-2.67%
Solana
Solana
SOL
$187.01
-3.18%
USDC
USDC
USDC
$0.9998
-0.02%
TRON
TRON
TRX
$0.3171
-1.30%
Dogecoin
Dogecoin
DOGE
$0.1895
-3.43%
Cardano
Cardano
ADA
$0.6475
-3.30%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter