Liquid Crypto Hack
Check if your address is affected.
Funds were stolen from users of Liquid Crypto (LQDX), a multichain liquidity protocol, on the 10th of January 2024. Its LiquidXv2Zap contracts exposed a deposit function that accepted an arbitrary account argument without checking that it matched the caller, so an attacker could call deposit on behalf of any wallet that had approved the zap and spend that approval to pull the wallet's tokens into a Liquid Crypto pool. SlowMist flagged the vulnerable zaps across several chains and Liquid Crypto redeployed new contracts, but the old zaps were left in place, so any approval to them should be revoked.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →