Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
BREAKING: LI.FI hit with an exploit, nearly $10 million drained so far

BREAKING: LI.FI hit with an exploit, nearly $10 million drained so far

Cryptobriefing2024/07/16 15:49
By: Cryptobriefing
XOLDTOKEN0.00%L0.00%

Key Takeaways

  • Li.fi protocol exploit has drained nearly $10 million, affecting users with infinite approvals.
  • Experts suspect a call injection attack, urging users to revoke approvals immediately.

Interoperability protocol Li.fi cautioned users not to interact with any applications using their infrastructure, as they are investigating a possible exploit underway. Only users that have manually set infinite approvals seem to be affected.

“Revoke all approvals for:

0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae

0x341e94069f53234fE6DabeF707aD424830525715

0xDE1E598b81620773454588B85D6b5D4eEC32573e

0x24ca98fB6972F5eE05f0dB00595c7f68D9FaFd68”

The first report of a possible exploit was given by the user identified on X as Sudo, who highlighted that nearly $10 million was drained from the protocol. Another X user identified as Wazz pointed out that Web3 wallet Rabby implemented Li.fi as its inbuilt bridge, warning users to check their permissions and revoke them. Notably, the Jumper Exchange is also a well-known application that uses Li.fi services.

Moreover, after blockchain security company CertiK shared on X the ongoing exploit, the user identified as Nick L. Franklin claimed that this is likely a “call injection” attack. A call injection attack consists of inserting a function name parameter from the original code on the client side of the application to execute any legitimate function from the code.

“Oh, call injection! Long time no seen. “swap” function didn’t check call target and call data. Because of this, users who approved to 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae lost their tokens, revoke approval asap! Also, Lifi router set this implementation recently,” said Nick.

According to the blockchain security firm PeckShield, the same hack was used against Li.fi back in March 2022.  March 20, 2022. “Are we learning anything from the past lesson(s)?”, stated PeckShield.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

CandyBomb x ZBT: Trade futures to share 100,000 ZBT!
Bitget Announcement2025/10/17 13:30
Bitget Builder+ Initiative is now recruiting!
Bitget Announcement2025/10/17 11:00

Trending news

More
1
CandyBomb x ZBT: Trade futures to share 100,000 ZBT!
2
Bitget Builder+ Initiative is now recruiting!

Crypto prices

More
Bitcoin
Bitcoin
BTC
$106,797.65
-1.42%
Ethereum
Ethereum
ETH
$3,843.03
-1.37%
Tether USDt
Tether USDt
USDT
$1
+0.03%
BNB
BNB
BNB
$1,073.92
-7.19%
XRP
XRP
XRP
$2.3
-0.84%
Solana
Solana
SOL
$182.66
-1.26%
USDC
USDC
USDC
$1.0000
+0.01%
TRON
TRON
TRX
$0.3091
-2.20%
Dogecoin
Dogecoin
DOGE
$0.1851
-1.92%
Cardano
Cardano
ADA
$0.6267
-2.80%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter