2022 LI.FI Hack
Check if your address is affected.
LI.FI is a service that finds the best route for moving tokens between blockchains by combining bridges and decentralized exchanges. About a month before the attack, LI.FI had launched its own smart contract, which could also swap tokens before bridging them. This swap feature was too flexible, because it let callers point it at any contract instead of only at exchanges. On 20 March 2022, an attacker used this to make the LI.FI contract move tokens like USDC, USDT, DAI and AAVE out of wallets that had given it unlimited approvals.
Around $600k was stolen in a single transaction on Ethereum, and the attacker swapped all of it into ETH. Once LI.FI noticed, it disabled all swap functions and warned users on Twitter. LI.FI took full responsibility and reimbursed all affected users, most of them within 18 hours. Some were also offered the option to turn their loss into an early investment in LI.FI instead of a cash refund. LI.FI also offered the attacker a bounty to return the funds, but had not received a response by the time of its post-mortem.
LI.FI fixed the contract in place the same day, so that it only allowed calls to a list of approved exchanges, and then turned swaps back on. It also stopped asking users for unlimited approvals by default. The same contract was also deployed on several other chains, and remaining approvals to it are no longer exploitable. You do not need to revoke them, although you can if you no longer use LI.FI.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →