📈 Get daily crypto insights that make you smarter about your money

LI.FI Protocol Drained of $11.6 Million in Smart Contract Facet Exploit

The cross-chain liquidity aggregation protocol LI.FI suffered a devastating security breach on July 16, 2024, losing approximately $11.6 million in user funds after a newly deployed smart contract facet contained a critical vulnerability. The attack targeted wallets that had previously granted infinite token approvals to the LI.FI contract, affecting 153 individual wallets across Ethereum and Arbitrum.

The Exploit Mechanics

The vulnerability originated from a flawed deployment of a new smart contract facet. According to LI.FI’s official incident report, the exploit was made possible by a missing validation check within the LibSwap library, which facilitates calls to multiple decentralized exchanges, fee collectors, and other entities before bridging or sending funds. In all other existing facets of the LI.FI contract, these external calls are validated against a whitelist of approved contract addresses and functions. However, due to what the team described as an individual human error during the deployment oversight process, this critical validation was absent from the new facet.

This omission allowed callers to the contract to make arbitrary calls to any external contract without validation. The attacker exploited this capability within minutes of the facet going live, draining USDC, USDT, and DAI from wallets that had previously set infinite token approvals for the LI.FI contract. With Bitcoin trading at approximately $65,097 and Ethereum at $3,443 at the time, the exploit sent ripples through the DeFi security community.

Affected Systems

The breach was confined to Ethereum and Arbitrum, where the vulnerable facet had been deployed. LI.FI emphasized that the vulnerability was limited exclusively to infinite approvals and did not affect finite approvals, which remain the default setting within the LI.FI API, SDK, and widget. The 153 affected wallets had all previously granted unlimited spending permissions to the LI.FI contract, a practice that security researchers have long warned against.

The attack vector is particularly concerning because it exploited a common user behavior rather than a novel cryptographic weakness. Infinite token approvals, while convenient for frequent DeFi users, create a persistent attack surface that compounds with every new contract interaction a protocol introduces.

The Mitigation Strategy

Upon detecting the breach, LI.FI’s team immediately activated their incident response plan and disabled the vulnerable facet across all chains. This swift action contained the threat and prevented further unauthorized access. The protocol also engaged with law enforcement authorities, blockchain security firms, and independent researchers to trace and attempt recovery of the stolen funds.

Notable security researchers and organizations including pcaversaccio, zeroshadow, SEAL Org, Hexagate, HypernativeLabs, and others assisted in identifying and addressing the vulnerability. LI.FI also announced that it was evaluating options to fully compensate affected users, backed by its major investors.

Lessons Learned

The LI.FI incident highlights several critical security principles for both protocols and users. First, deployment oversight must include redundant validation checks, particularly for facets that handle arbitrary external calls. A single human error in the review process should not be sufficient to bypass security guardrails. Second, the incident reinforces the danger of infinite token approvals. Users who had granted only finite, per-transaction approvals were entirely unaffected by this exploit. Third, rapid incident response proved essential in limiting the damage.

For DeFi protocols managing cross-chain operations, the LI.FI exploit serves as a stark reminder that the complexity of multi-chain interactions amplifies the attack surface. Each new chain integration and each new contract facet introduces potential failure points that must be rigorously tested before deployment.

User Action Required

Users who interact with any cross-chain bridge or aggregator should immediately review their token approvals. Tools like Revoke.cash and Etherscan’s token approval checker allow users to identify and revoke infinite approvals. Replace them with finite approvals for each transaction, or use protocols that default to per-transaction spending limits. This single practice would have prevented losses for all 153 wallets affected by the LI.FI exploit. As the DeFi ecosystem continues to grow, with total value locked surging past $90 billion, personal security hygiene remains the most effective defense against smart contract vulnerabilities.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before interacting with any DeFi protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “LI.FI Protocol Drained of $11.6 Million in Smart Contract Facet Exploit”

    1. audits catch known patterns. this was described as individual human error during deployment. different problem entirely

      1. Mike T. exactly. the audit covered existing facets. the new one shipped without the LibSwap validation that every other facet had. process failure not audit failure

      2. individual human error during deployment. this is why multi-sig and time locks exist. one person shouldnt be able to ship a facet solo

        1. multi-sig deployment is standard at every serious protocol now. one person shipping a facet solo is a process failure not just a human error

          1. libswap_witness_

            deploy_guard one person shipping a facet solo is wild for a protocol handling cross-chain liquidity. where was the multisig review

          2. libswap_autopsy_

            deploy_guard one person shipping a facet solo for a cross-chain protocol handling millions is wild. where was the multisig review on the deployment

      3. deploy_sentry

        Mike T. audits catch patterns but the deployment process failed here, not the audit. you can audit every facet and still ship a vulnerable one if one person bypasses review

    2. a single missing whitelist check in LibSwap and 153 wallets across ethereum and arbitrum got drained. the audit caught everything except the one facet nobody reviewed

  1. 153 wallets drained because of infinite approvals. revoke your old token permissions people, it takes 2 minutes on revoke.cash

    1. infinite approvals are a ticking time bomb. set approvals to exact amounts or use ephemeral approvals. no excuse in 2024

      1. revoke_now 153 wallets because they all clicked approve once months ago and forgot. infinite approvals are a structural failure not user error

      2. exact amount approvals should be the default in every wallet UI. infinite approvals are a relic from 2020 gas optimization that should have been killed years ago

        1. Pranav G. exact amount approvals are the answer but the UX cost is real. every wallet forces you to calculate gas plus allowance manually. the defaults need to change at the protocol level not just wallet UI

        2. Pranav G. exact approvals should be the default but wallets make it 5 clicks vs 1 click for infinite. the UX defaults are the actual security vulnerability

          1. approval_burn_

            Felipe D. wallet UX makes infinite approval one click and exact approval takes 5 forms. the defaults are actively hostile to security. no wonder 153 wallets got drained

    2. deadwallet_404

      catlover88 2 minutes on revoke.cash vs 11.6 million gone. the UX problem is that exact approvals cost more gas so everyone picks infinite

  2. approvals_goblin

    153 wallets because of infinite approvals. this exploit format is older than most defi protocols and people still dont revoke

    1. approvals_goblin 153 wallets hit because of infinite approvals and people still wont spend 2 minutes on revoke.cash

  3. The single missing validation check in LibSwap was the root cause. One oversight and $11.6M gone. This shows security needs to be systemic.

    1. SecurityMaxi exactly. one missing whitelist check in LibSwap and 11.6M gone. security has to be enforced at deployment not just audit time

  4. Deployment process failed, not the audit. You can have perfect audits but still fail if deployment bypasses controls.

  5. ExactApprovals

    Exact amount approvals should be the default everywhere. The UX cost of 2 minutes on revoke.cash is worth billions in security.

  6. LibSwap validation missing from one facet. every other facet had the whitelist check. one deployment oversight, 11.6 million gone

    1. 153_wallets_later_

      facet_audit_ human error during deployment is the root cause of like 70 percent of defi exploits. the code was fine, the process was broken

  7. every other facet had the LibSwap whitelist check. the one facet that shipped without it drained 11.6M from 153 wallets. deployment governance is the actual bug

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,295.00+0.2%ETH$2,504.76-0.8%SOL$100.97-0.9%BNB$720.68-1.4%XRP$1.35-0.8%ADA$0.2084+0.2%DOGE$0.0844-0.6%DOT$1.02-0.7%AVAX$7.42+0.4%LINK$11.40-1.0%UNI$6.32+0.1%ATOM$1.61-1.3%LTC$54.66+1.5%ARB$0.1396-0.9%NEAR$2.35-1.0%FIL$0.9748+21.3%SUI$0.7198-0.6%BTC$77,295.00+0.2%ETH$2,504.76-0.8%SOL$100.97-0.9%BNB$720.68-1.4%XRP$1.35-0.8%ADA$0.2084+0.2%DOGE$0.0844-0.6%DOT$1.02-0.7%AVAX$7.42+0.4%LINK$11.40-1.0%UNI$6.32+0.1%ATOM$1.61-1.3%LTC$54.66+1.5%ARB$0.1396-0.9%NEAR$2.35-1.0%FIL$0.9748+21.3%SUI$0.7198-0.6%
Scroll to Top