Li.Fi Protocol Hacked, Resulting in $10 Million Loss

Li.Fi, an API for Ethereum Virtual Machine and Solana swaps and bridging, was hacked on July 16, resulting in over $10 million in cryptocurrency being drained.

Azcnews Lifi Protocol Hacked, Resulting In $10 Million Loss

According to Cyvers, their system flagged suspicious transactions on Li.Fi involving a specific contract address.

Cyvers recommended users revoke approvals for the suspicious address: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae

Meir Dolev, co-founder and CTO at Cyvers, emphasized the need for constant vigilance from protocols:

“Hackers can exploit these approvals to drain assets stored in the contract as well as funds in connected user wallets.”

Li.Fi Alert

In a post on X on July 16, Li.Fi warned users not to interact with applications powered by Li.Fi until further notice. During the ongoing attack, the team explained they were investigating the vulnerability and clarified that users without “infinite approvals” would not be at risk.

For users who had set up infinite approvals, the Li.Fi team advised revoking the following addresses:

  • 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae
  • 0x341e94069f53234fE6DabeF707aD424830525715
  • 0xDE1E598b81620773454588B85D6b5D4eEC32573e
  • 0x24ca98fB6972F5eE05f0dB00595c7f68D9FaFd68

At 11:44 AM ET (15:44 UTC), Li.Fi updated its users via a post on X stating that the smart contract vulnerability had been mitigated. “There is no further risk to users at this time,” the post read. “Only wallets with infinite approvals were affected, representing a very small number of users.”

$10 Million Drained

According to Cyvers, approximately $10 million in cryptocurrency was drained, also affecting the Arbitrum blockchain. Dolev remarked, “This incident underscores the inherent risks in granting wallet permissions to smart contracts.”

In an update post on X, Cyvers once again urged users to revoke the address 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae to prevent further losses.

From Drains to Flash Loan Attacks

The decentralized finance protocol Dough Finance was recently attacked on July 12, falling victim to a $1.8 million flash loan attack. Cyvers reported on the incident, explaining that the attacker financed the exploit through the zero-knowledge protocol Railgun and swapped the stolen USD Coin.

According to Web3 security provider Olympix, the vulnerability accumulated 608 ETH, valued at approximately $1.8 million, originating from unverified call data with “ConnectorDeleverageParaswap.”

0.0/5

Love

Latest

Azcnews Breaking Litecoin Transactions Soar 243% In Five Months Amid Etf Speculation

News | Altcoin | Editor Choice

Litecoin Transactions Soar 243% in Five Months Amid ETF Speculation

Litecoin's price surged over 8% following Canary’s latest move to position its spot Litecoin ETF for potential approval.

Guide To Participating In Monad Testnet

Airdrops | Editor Choice

Guide to Participating in Monad Testnet

Monad - A Layer 1 blockchain that has successfully raised $244 million is launching its testnet, giving users a chance to receive airdrops when the project goes mainnet.

Azcnews Breaking Will Pi Coin Reach $10 After The Open Mainnet Launch

News | Altcoin | Editor Choice

Will Pi Coin Reach $10 After the Open Mainnet Launch?

Pi Network officially launched its mainnet in February, but the price performance left early miners disappointed, plummeting by 55%. With such a rocky start, could Pi Coin still reach an all-time high (ATH) of $10 in the near future?

Azcnews Breaking Bitcoin Nears $100k Amid Rising Usdt Inflows

News | Bitcoin | Editor Choice

Bitcoin Nears $100K Amid Rising USDT Inflows

Bitcoin has surged to $98K, fueled by rising USDT liquidity and renewed capital inflows into exchanges. However, increasing leverage and weak Spot demand pose risks of heightened volatility.

Azcnews Breaking Ceo Coinbase Explains Why Bitcoin Is A Meme Coin

News | Bitcoin | Editor Choice | Memecoin

CEO Coinbase Explains Why Bitcoin Is a Meme Coin

Coinbase CEO Brian Armstrong has drawn an intriguing comparison between meme coins and early internet novelties, arguing that Bitcoin itself can be considered a meme asset.