Refreshed 3h ago· updates every 6h

LI.FI (2024) — Crypto Hack

Laundered
Jul 16, 2024·
EthereumArbitrumOptimismBasePolygon
Amount Stolen
$11.6M
~$11.6M in various tokens across multiple chains
Recovered
$0

LI.FI, a cross-chain bridge and DEX aggregator, was exploited for ~$11.6M after attackers tricked users into signing malicious permit signatures that drained their wallets.

Summary

LI.FI, a cross-chain bridge and DEX aggregator, was exploited for ~$11.6M after attackers tricked users into signing malicious permit signatures that drained their wallets.

How It Was Compromised — Bridge / Aggregator via Smart Contract Exploit / Phishing Signature

Bridge / AggregatorSmart Contract Exploit / Phishing Signature

On July 16, 2024, LI.FI, a cross-chain bridge and DEX aggregator, was exploited for approximately $11.6M. The attack was not a direct smart contract exploit but rather a sophisticated phishing attack that tricked users into signing malicious permit signatures (setApprovalForAll) that granted the attacker approval to drain the users' wallets. The attacker targeted users who had interacted with LI.FI's contracts across multiple chains including Ethereum, Arbitrum, Optimism, Base, and Polygon. LI.FI identified the vulnerability in their smart contract that allowed the malicious approvals to be processed and patched it within hours.

Fund Flow & Laundering Analysis

Stolen tokens were swapped to ETH and stablecoins via decentralized exchanges across the affected chains. The funds were then bridged to Ethereum mainnet and deposited into Tornado Cash. The attacker used a complex network of intermediary wallets to fragment the laundering trail. LI.FI engaged with blockchain analytics firms and offered a bounty for information leading to the recovery of the funds.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.