{"investigation":{"slug":"lifi-finance","entity_name":"LiFi Finance","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"LI.FI is a Berlin-based cross-chain bridge and DEX aggregation protocol founded in 2021 by Philipp Zentner and Max Klenk. The protocol has suffered two significant smart contract exploits — a $600,000 loss in March 2022 and an $11.6 million loss in July 2024 — both stemming from the same class of arbitrary-call vulnerability, prompting criticism from security researchers that lessons were not learned. Separately, blockchain investigator ZachXBT alleged in June 2025 that North Korean (DPRK) actors accounted for an estimated 15–25% of the protocol's volume during May 2025, using LI.FI to launder funds from the Bybit hack.","sections":[{"content":"LI.FI (also styled as Li.Fi or Li Finance) is a cross-chain liquidity aggregation and orchestration protocol that aggregates bridges and decentralized exchanges into a single API, SDK, and embeddable widget. The protocol supports 60+ blockchain networks and routes swaps and transfers across 20+ bridges and 20+ DEX aggregators. LI.FI was incorporated in Berlin, Germany in 2021 and is co-founded by Philipp Zentner (CEO) and Max Klenk (CTO). As of late 2025, the protocol reports over 1,000 B2B integration partners including Robinhood, Binance, Kraken, MetaMask, Phantom, Ledger, and Circle, and claims to have processed over $60 billion in cumulative transfer volume. The protocol does not have a publicly traded native token as of mid-2026. LI.FI has raised a total of approximately $51.7 million across funding rounds, including a $17.5 million Series A in March 2023 and a $29 million Series A extension in December 2025 co-led by Multicoin Capital and CoinFund.","heading":"Protocol Overview","sources":[{"url":"https://li.fi/about-us/","name":"li.fi","type":"other","credibility":3},{"url":"https://www.prnewswire.com/news-releases/lifi-secures-29m-in-series-a-extension-led-by-multicoin-and-coinfund-to-scale-the-universal-liquidity-market-for-digital-assets-302639425.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 20, 2022, LI.FI suffered its first major smart contract exploit. An attacker targeted the protocol's swapping feature, which allowed token swaps before bridging. By calling token contracts directly within the context of the LI.FI contract — without actually performing any swap — the attacker was able to drain tokens from wallets that had granted infinite approval to the protocol. The exploit was executed in a single transaction at approximately 02:51 AM UTC. Approximately $600,000 was stolen from 29 wallets. Stolen assets included USDC, MATIC, RPL, GNO, USDT, MVI, AUDIO, AAVE, JRT, and DAI. Upon discovery, the team disabled all swap methods in their smart contract. Of the 29 affected wallets, 25 were reimbursed from treasury funds for approximately $80,000, representing about 13% of total losses. The remaining four wallets, which collectively lost approximately $517,000, were offered an arrangement to convert their losses into angel investments in LI.FI under early-investor terms. LI.FI published a post-mortem report on its blog.","heading":"2022 Smart Contract Exploit ($600,000)","sources":[{"url":"https://blog.li.fi/20th-march-the-exploit-e9e1c5c03eb9","name":"blog.li.fi","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/hacker-drained-600k-worth-of-crypto-from-li-finance/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi","name":"revoke.cash","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 16, 2024, LI.FI suffered a second major smart contract exploit, resulting in approximately $11.6 million stolen from 153 wallets across the Ethereum and Arbitrum networks. The breach occurred five days after the protocol deployed a new contract component, GasZipFacet. The root cause was that the function `depositToGasZipERC20()` in GasZipFacet.sol passed user-controlled `_swapData` directly to `LibSwap.swap`, which contained a low-level call capable of executing arbitrary functions against any contract. Unlike all other facets in the LI.FI contract at the time, GasZipFacet lacked the whitelist validation checks that restrict which contract addresses and function selectors can be invoked. Because `_swap.callTo` and `_swap.callData` were user-controlled, the attacker crafted malicious calldata that called `transferFrom()` on token contracts, draining USDC, USDT, and DAI from wallets with pre-existing infinite token approvals. The protocol immediately disabled the vulnerable facet upon detection and engaged law enforcement and third-party security partners. LI.FI initiated a voluntary compensation plan, with affected users asked to complete a form and offered options including direct treasury reimbursement or conversion of losses into early-stage angel investment terms in LI.FI tokens. Security firm PeckShield publicly noted the exploit was 'basically the same' vulnerability class as the 2022 incident, writing 'Are we learning anything from the past lesson(s)?'","heading":"2024 Smart Contract Exploit ($11.6 Million)","sources":[{"url":"https://li.fi/knowledge-hub/incident-report-16th-july/","name":"li.fi","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/07/16/defi-protocol-lifi-struck-by-8m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/240017/defi-protocol-lifi-hacked-9-million-ethereum-stablecoins","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/lifi-releases-incident-report-following-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://threesigma.xyz/blog/exploit/lifi-9m-protocol-exploit-analysis","name":"threesigma.xyz","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Independent security researchers and blockchain analytics firms have noted that both the 2022 and 2024 exploits exploited the same class of vulnerability: the ability to make arbitrary external calls from within the LI.FI contract using user-controlled calldata, without adequate whitelist validation. QuillAudits published an analysis titled 'Same Mistake Twice: Decoding LiFi Protocol's $9.7M Exploit,' arguing that a root-cause class fix was not applied after the 2022 incident. PeckShield's characterization that the 2024 exploit was 'basically the same' as the 2022 incident drew significant community attention. LI.FI's own post-mortem for the 2024 incident attributes the failure to 'an individual human error in overseeing the deployment process,' noting that whitelist validation checks existed elsewhere in the codebase (in the SwapperV2 contract's Helpers folder) but were absent from the new LibSwap-based facet. The protocol had conducted multiple external audits by firms including Spearbit, Code4rena, and Quantstamp, and maintained a $1 million bug bounty program on Immunefi prior to the 2024 exploit. Critics argue the repeated nature of the vulnerability raises questions about deployment review procedures.","heading":"Repeated Vulnerability Class: Security Process Criticism","sources":[{"url":"https://quillaudits.medium.com/same-mistake-twice-decoding-lifi-protocols-9-7m-exploit-78835e166d23","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/li-fi-hack-analysis-521388128d22/","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/li-fi-launches-usd1million-bug-bounty-program-on-immunefi/","name":"li.fi","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 3, 2025, blockchain investigator ZachXBT alleged that North Korean (DPRK) state-sponsored hackers used LI.FI as a laundering conduit for proceeds from the February 2025 Bybit hack, which saw approximately $1.4 billion stolen. ZachXBT stated that DPRK actors represented 'at minimum 15–25% of LiFi activity' during May 2025, the same month LI.FI reported record performance of $3 billion in volume and 4.37 million transactions. ZachXBT characterized the volume inflation as partly illusory, stating: 'Usage gets overstated because they repeatedly chain hop back and forth to obfuscate movements.' He further alleged that by the end of May 2025, over half of the $1.4 billion stolen in the Bybit incident had become untraceable on-chain, suggesting successful laundering through protocols including LI.FI. ZachXBT's underlying concern was that LI.FI and its founder were presenting this record volume as evidence of growth without disclosing the alleged source of a significant portion of that activity. LI.FI's founder and team reportedly stated they had been attempting to reduce hacker-linked volumes, though the protocol's permissionless architecture provides limited screening capability by design. These allegations have not been independently confirmed by law enforcement or a regulatory authority as of mid-2026 and should be treated as alleged.","heading":"ZachXBT: Alleged DPRK Money Laundering via LI.FI","sources":[{"url":"https://crypto.news/zachxbt-links-lifi-volume-surge-to-dprk-laundering-post-bybit-hack/","name":"crypto.news","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/zachxbt-links-lifi-volume-surge-to-dprk-laundering-post-bybit-hack/","name":"bitcoinethereumnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"LI.FI was founded in 2021 by Philipp Zentner (CEO) and Max Klenk (CTO), both of whom had previously collaborated on other ventures. Zentner holds a degree in Business Computing from Universität Passau and began his career as a web developer in 2002. The company is headquartered in Berlin, Germany. LI.FI raised a $5.5 million seed round in July 2022, a $17.5 million Series A in March 2023 co-led by CoinFund and Superscrypt, and a $29 million Series A extension in December 2025 co-led by Multicoin Capital and CoinFund, with participation from Circle, L1D, and Factor[e] Ventures. Total capital raised stands at approximately $51.7 million. No regulatory actions by the SEC, CFTC, or other government bodies against LI.FI or its principals have been identified as of mid-2026.","heading":"Funding and Corporate Background","sources":[{"url":"https://www.prnewswire.com/news-releases/lifi-raises-17-5-million-series-a-to-help-traditional-finance-build-on-defi-301788542.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/382242/multicoin-joins-as-lead-investor-in-li-fis-29-million-series-a-extension-round","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/li-finance-fbae","name":"crunchbase.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of mid-2026, LI.FI remains operational and continues to expand its partner network and supported blockchain coverage (60+ chains). Following the July 2024 exploit, the protocol implemented additional monitoring infrastructure including automated threat detection, anomaly detection using baseline behavioral models, and emergency pause mechanisms. The company has continued to attract institutional investment, raising $29 million in December 2025 with participation from regulated entities including Circle. However, the protocol faces ongoing reputational risk stemming from two exploits attributable to the same vulnerability class, and unresolved allegations from ZachXBT regarding DPRK money laundering through its infrastructure. Users who have granted infinite token approvals to LI.FI smart contracts in the past are advised to revoke those approvals using tools such as Revoke.cash, as residual approvals may expose them to future exploit risk. No formal regulatory action or criminal charges have been identified against LI.FI or its principals as of mid-2026.","heading":"Current Status and Risk Posture","sources":[{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/li-fi-update-december-2025/","name":"li.fi","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"LI.FI founded in Berlin, Germany by Philipp Zentner and Max Klenk.","source":"","date_original":"2021-01-01"},{"date":"2022-03-20","event":"First exploit: attacker drains approximately $600,000 from 29 wallets using arbitrary call vulnerability in the swapping feature. LI.FI disables swap methods and publishes post-mortem.","source":""},{"date":"2022-07","event":"LI.FI raises $5.5 million seed round led by 1kx.","source":"","date_original":"2022-07-01"},{"date":"2023-03","event":"LI.FI raises $17.5 million Series A co-led by CoinFund and Superscrypt.","source":"","date_original":"2023-03-01"},{"date":"2024-07-11","event":"LI.FI deploys new GasZipFacet smart contract component, missing whitelist validation present in other facets.","source":""},{"date":"2024-07-16","event":"Second exploit: attacker exploits GasZipFacet arbitrary call vulnerability, draining approximately $11.6 million from 153 wallets on Ethereum and Arbitrum. Protocol immediately disables vulnerable facet. PeckShield characterizes it as 'basically the same' bug as 2022.","source":""},{"date":"2024-07-18","event":"LI.FI announces voluntary compensation plan for the 153 affected wallets, backed by major investors.","source":""},{"date":"2025-02","event":"Bybit exchange suffers approximately $1.4 billion hack attributed to North Korean Lazarus Group.","source":"","date_original":"2025-02-01"},{"date":"2025-05","event":"LI.FI reports record May 2025 metrics: $3 billion in volume and 4.37 million executed transactions.","source":"","date_original":"2025-05-01"},{"date":"2025-06-03","event":"ZachXBT publicly alleges that DPRK hackers laundering Bybit hack proceeds accounted for 15–25% of LI.FI's May 2025 activity, and that over half of Bybit stolen funds had become untraceable on-chain.","source":""},{"date":"2025-12-11","event":"LI.FI raises $29 million Series A extension led by Multicoin Capital and CoinFund, bringing total capital raised to approximately $51.7 million.","source":""}],"sources_used":[{"url":"https://li.fi/about-us/","name":"li.fi","type":"other","archive_url":"http://web.archive.org/web/20260608125246/https://li.fi/about-us","credibility":3,"archive_timestamp":"2026-06-08T12:52:46+00:00"},{"url":"https://www.prnewswire.com/news-releases/lifi-secures-29m-in-series-a-extension-led-by-multicoin-and-coinfund-to-scale-the-universal-liquidity-market-for-digital-assets-302639425.html","name":"prnewswire.com","type":"other","archive_url":"http://web.archive.org/web/20251229212931/https://www.prnewswire.com/news-releases/lifi-secures-29m-in-series-a-extension-led-by-multicoin-and-coinfund-to-scale-the-universal-liquidity-market-for-digital-assets-302639425.html","credibility":3,"archive_timestamp":"2025-12-29T21:29:31+00:00"},{"url":"https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260101061005/https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","credibility":3,"archive_timestamp":"2026-01-01T06:10:05+00:00"},{"url":"https://blog.li.fi/20th-march-the-exploit-e9e1c5c03eb9","name":"blog.li.fi","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260829234214/https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit","credibility":3,"archive_timestamp":"2026-08-29T23:42:14+00:00"},{"url":"https://cryptopotato.com/hacker-drained-600k-worth-of-crypto-from-li-finance/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260608145958/https://cryptopotato.com/hacker-drained-600k-worth-of-crypto-from-li-finance/","credibility":3,"archive_timestamp":"2026-06-08T14:59:58+00:00"},{"url":"https://revoke.cash/exploits/lifi","name":"revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260314131926/https://revoke.cash/exploits/lifi","credibility":3,"archive_timestamp":"2026-03-14T13:19:26+00:00"},{"url":"https://li.fi/knowledge-hub/incident-report-16th-july/","name":"li.fi","type":"other","archive_url":"http://web.archive.org/web/20260820173651/https://li.fi/knowledge-hub/incident-report-16th-july","credibility":3,"archive_timestamp":"2026-08-20T17:36:51+00:00"},{"url":"https://www.coindesk.com/business/2024/07/16/defi-protocol-lifi-struck-by-8m-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251228013110/https://www.coindesk.com/business/2024/07/16/defi-protocol-lifi-struck-by-8m-exploit","credibility":3,"archive_timestamp":"2025-12-28T01:31:10+00:00"},{"url":"https://decrypt.co/240017/defi-protocol-lifi-hacked-9-million-ethereum-stablecoins","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260410095556/https://decrypt.co/240017/defi-protocol-lifi-hacked-9-million-ethereum-stablecoins","credibility":3,"archive_timestamp":"2026-04-10T09:55:56+00:00"},{"url":"https://cointelegraph.com/news/lifi-releases-incident-report-following-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260216170358/https://cointelegraph.com/news/lifi-releases-incident-report-following-hack","credibility":3,"archive_timestamp":"2026-02-16T17:03:58+00:00"},{"url":"https://threesigma.xyz/blog/exploit/lifi-9m-protocol-exploit-analysis","name":"threesigma.xyz","type":"other","archive_url":"http://web.archive.org/web/20260415074326/https://threesigma.xyz/blog/exploit/lifi-9m-protocol-exploit-analysis","credibility":3,"archive_timestamp":"2026-04-15T07:43:26+00:00"},{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260517030910/https://revoke.cash/exploits/lifi-2024","credibility":3,"archive_timestamp":"2026-05-17T03:09:10+00:00"},{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260830042010/https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","credibility":3,"archive_timestamp":"2026-08-30T04:20:10+00:00"},{"url":"https://quillaudits.medium.com/same-mistake-twice-decoding-lifi-protocols-9-7m-exploit-78835e166d23","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017175915/https://quillaudits.medium.com/same-mistake-twice-decoding-lifi-protocols-9-7m-exploit-78835e166d23","credibility":3,"archive_timestamp":"2025-10-17T17:59:15+00:00"},{"url":"https://blog.solidityscan.com/li-fi-hack-analysis-521388128d22/","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20260819234032/https://blog.solidityscan.com/li-fi-hack-analysis-521388128d22/","credibility":3,"archive_timestamp":"2026-08-19T23:40:32+00:00"},{"url":"https://li.fi/knowledge-hub/li-fi-launches-usd1million-bug-bounty-program-on-immunefi/","name":"li.fi","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://crypto.news/zachxbt-links-lifi-volume-surge-to-dprk-laundering-post-bybit-hack/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251019061656/https://crypto.news/zachxbt-links-lifi-volume-surge-to-dprk-laundering-post-bybit-hack/","credibility":3,"archive_timestamp":"2025-10-19T06:16:56+00:00"},{"url":"https://bitcoinethereumnews.com/tech/zachxbt-links-lifi-volume-surge-to-dprk-laundering-post-bybit-hack/","name":"bitcoinethereumnews.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.prnewswire.com/news-releases/lifi-raises-17-5-million-series-a-to-help-traditional-finance-build-on-defi-301788542.html","name":"prnewswire.com","type":"other","archive_url":"http://web.archive.org/web/20251109214754/https://www.prnewswire.com/news-releases/lifi-raises-17-5-million-series-a-to-help-traditional-finance-build-on-defi-301788542.html","credibility":3,"archive_timestamp":"2025-11-09T21:47:54+00:00"},{"url":"https://www.theblock.co/post/382242/multicoin-joins-as-lead-investor-in-li-fis-29-million-series-a-extension-round","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260727145335/https://www.theblock.co/post/382242/multicoin-joins-as-lead-investor-in-li-fis-29-million-series-a-extension-round","credibility":3,"archive_timestamp":"2026-07-27T14:53:35+00:00"},{"url":"https://www.crunchbase.com/organization/li-finance-fbae","name":"crunchbase.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://li.fi/knowledge-hub/li-fi-update-december-2025/","name":"li.fi","type":"other","archive_url":"http://web.archive.org/web/20260109104354/https://li.fi/knowledge-hub/li-fi-update-december-2025/","credibility":3,"archive_timestamp":"2026-01-09T10:43:54+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:31.018387+00:00","updated_at":"2026-08-30T05:14:07.203968+00:00"}}