Li Finance protocol loses $600,000 in latest DeFi exploit

Share This Post

Li Finance (LiFi) protocol users suffered losses amounting to around $600,000, some of them have been reimbursed after a hacker exploited a bug in the project’s smart contract.

The Li Finance swap aggregator has experienced a smart contract exploit leading to the loss of around $600,000 from 29 users’ wallets.

The exploit took place at 2:51 am UTC on March 20. The attacker was able to extract varying amounts of 10 different tokens from wallets that had given “infinite approval” to the Li Finance protocol. Among the stolen tokens were USD Coin (USDC), Polygon (MATIC), Rocket Pool (RPL), Gnosis (GNO), Tether (USDT), Metaverse Index (MVI), Audius (AUDIO), AAVE (AAVE), Jarvis Reward Token (JRT), and DAI (DAI).

When the team learned about the exploit 12 hours later at 2:15 pm UTC, it shut down all swapping functions on the platform in order to prevent any further losses.

By 2:50 am UTC on March 21, the team had issued a post mortem detailing the events of the exploit. The team said that the attacker swapped the stolen tokens for a total of about 205 Ether (ETH) valued at roughly $600,000. At the time of writing, the stolen ETH had yet to be moved from the attacker’s wallet. LiFi also assured users that the bug has been identified and patched.

Of the 29 wallets that were hit in this attack, 25 have been reimbursed from treasury funds for their losses. Those 25 wallets only accounted for $80,000, or 13% of the total value lost. The owners of the remaining four wallets that lost a combined $517,000 have been contacted and offered a deal to compensate them by honoring their losses as angel investors in the protocol.

They would receive LiFi tokens under the same terms as other angel investors in an amount equal to their losses from each wallet. This would also help to mitigate the damage to the platform’s treasury.

The hacker was also contacted and offered a bug bounty to return the funds.

The Li Finance team reached out to offer a bug bounty to a hacker.

The attack appears to have come at an unfortunate time. Li Finance CEO Philipp Zentner told Cointelegraph on March 21 that “We’re literally a week away from our audit,” adding that “we have multiple companies auditing us.”

However, even a thorough audit of the code may not have picked up this particular bug, according to a researcher “Transmissions11” at crypto investment firm Paradigm. He explained in a March 21 tweet that the error in Li Finance’s code is easy to miss and “subtle if you’re not in the right mindset.”

Related: ‘Unlucky:’ Agave and Hundred Finance DeFi protocols exploited for $11M

This latest hack in the decentralized finance (DeFi) sector demonstrates how giving infinite approvals to smart contracts opens a user’s funds to a greater amount of risk. Infinite approvals allow users to swap coins at a decentralized exchange (DEX) an unlimited amount of times without needing to approve any more transactions.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Solana (SOL) and Ripple (XRP) Investors Pivot to Online Gaming Platform Rumored To Lead 2024’s Next Bull Run

The post Solana (SOL) and Ripple (XRP) Investors Pivot to Online Gaming Platform Rumored To Lead 2024’s Next Bull Run appeared first on Coinpedia Fintech News The crypto markets are back in

Trending Ethereum Token LNEX Sees Price Surge as SUI Price Action Stalls: What’s Driving the Shift?

The post Trending Ethereum Token LNEX Sees Price Surge as SUI Price Action Stalls: What’s Driving the Shift appeared first on Coinpedia Fintech News Ethereum investors are regaining interest as

Market Volatility May Intensify in Next 48 Hours-Here’s What to Expect from the Bitcoin Price Rally This Weekend

The post Market Volatility May Intensify in Next 48 Hours-Here’s What to Expect from the Bitcoin Price Rally This Weekend appeared first on Coinpedia Fintech News The bitcoin price is falling back

Bitcoin Options Traders Set Sights On $80,000 By November-End, Regardless Of US Election Outcome

As the US presidential election approaches, the crypto community is buzzing with speculation regarding how the outcome will affect the Bitcoin price  With just 15 days until the election between

Japanese Entertainment Giant’s Crypto Arm in Partnerships to Support Web3 Economy

Japanese cryptocurrency exchange DMM Crypto has secured Neoclassic Capital, a Florida-based global investment firm, as its lead investor DMM Crypto also partnered with Presto, a quantitative trading

Vitalik Buterin Slams Saylor’s Bitcoin Custody Proposal as ‘Insane

The post Vitalik Buterin Slams Saylor’s Bitcoin Custody Proposal as ‘Insane appeared first on Coinpedia Fintech News MicroStrategy’s Michael Saylor is under fire for suggesting Bitcoin