CryptoReal
CASE FILE — Jul 16, 2024

Recycled Vulnerability Costs LiFi Protocol $9.73M in Cross-Chain Approval Drain

Cross-chain infrastructure provider LiFi lost $9.73 million after an attacker exploited previously granted infinite token approvals, draining wallets across several blockchains that had authorized the protocol's contracts.

Security firm CertiK flagged unusual activity first, and the LiFi team confirmed the incident roughly an hour afterward. Jumper Exchange, a front-end product that relies on LiFi's routing, notified its own users shortly after and later stated it had not been directly impacted. Both teams advised affected users to review their approvals and use revoke.cash to cut off the compromised contract's permissions.

Notably, this was not LiFi's first brush with this exact failure mode. Back in March 2022, LiFi suffered an almost identical exploit that cost 29 wallets a combined $600,000.

How the exploit unfolded

The root cause traced back to July 11, when a new contract facet was deployed as part of LiFi's protocol. That addition introduced a "swap" function with insufficient input validation, as security researcher Nick L. Franklin later detailed.

Specifically, the new contract never properly verified the call target or the call data supplied to it, opening the door to a "call injection" attack. By exploiting this gap, the attacker was able to trigger arbitrary function calls using whatever permissions had been granted to the LiFi contract — meaning any wallet that had approved unlimited spending for that contract was exposed to having its tokens moved without further consent.

Attacker address: 0x8B3Cb6Bf982798fba233Bca56749e22EEc42DcF3

Contracts affected by chain:

Sums referenced in this case file

The attacker's haul consisted of USDT, USDC, and DAI totaling roughly $9.73 million, which was subsequently converted into 2,857 ETH. Those funds were then spread across a number of wallets under the attacker's control.

A pattern across bridge protocols

This incident follows a similar playbook to the $3.3 million Socket protocol hack on January 16, reinforcing that cross-chain bridges and aggregators remain high-value targets. In that earlier case, the attacker also went after wallets that had granted infinite approvals to Socket's contracts, exploiting a route added shortly before the attack.

Peckshield's analysis drew a direct line between the two incidents, noting the structural similarity to the earlier LiFi breach.

Ironically, LiFi's own post-mortem from the 2022 incident described the remediation it had put in place: "We then implemented a whitelist to only allow calls to approved DEXs. Our contract was upgraded to include this new whitelist functionality, and swaps were reenabled. On top of that, we have disabled infinite approvals by default." Whether the newly added contract facet from July 11 underwent an audit has not been disclosed.

Aftermath

LiFi maintained that only a small subset of users — those who had left infinite approvals in place — were affected, though the scale of the loss suggests the practice was more widespread among its user base than the framing implies.

The episode underscores a recurring risk in DeFi: wallets that grant standing, unlimited approvals to a protocol remain exposed for as long as that approval sits unrevoked, regardless of whether the protocol is actively used. Tools like revoke.cash exist specifically to let users audit and clear such permissions, but the incident also highlights that an unaudited contract upgrade to an already-approved protocol can undo any amount of user-side caution.

Jumper ExchangeLiFi Protocol
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.