{"investigation":{"slug":"lifi-protocol","entity_name":"LiFi Protocol","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"LI.FI (formerly Li.Finance) is a cross-chain liquidity aggregation protocol founded in 2021 that routes swaps across bridges and DEXs via a unified API, SDK, and widget. The protocol has suffered two distinct smart contract exploits — a $600,000 approval drain in March 2022 and an approximately $11.6 million drain in July 2024 — with security firm PeckShield noting the root causes were 'basically the same.' Both incidents involved arbitrary-call vulnerabilities that allowed attackers to abuse users' infinite token approvals, raising concerns about repeated security failures despite prior disclosure.","sections":[{"content":"LI.FI is a cross-chain bridge and DEX aggregation layer founded in 2021 by Philipp Zentner (CEO) and operates as a B2B infrastructure provider, offering an API, SDK, and embeddable widget to third-party applications. The protocol aggregates liquidity from major bridges such as Stargate and Across, as well as DEX aggregators including 1inch and Uniswap, routing optimal cross-chain swap paths for integrated applications. As of late 2025, LI.FI reported over $60 billion in lifetime transaction volume and claimed integration with approximately 1,000 B2B partners including Robinhood, MetaMask, Binance, Kraken, Phantom, and Ledger. The protocol is built around a diamond proxy (EIP-2535) architecture that allows modular smart contract facets to be added or upgraded. This architectural choice has been a factor in both security incidents. The LIFI native token had not officially launched as of early 2026; the project uses an XP-based loyalty points system in the interim.","heading":"Protocol Overview","sources":[{"url":"https://li.fi/","name":"li.fi","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/li-fi-secures-usd29m-in-series-a-extension-led-by-multicoin-and-coinfund-to/","name":"li.fi","type":"other","credibility":3},{"url":"https://stablecoininsider.org/lifi-cross-chain-aggregator-2026/","name":"stablecoininsider.org","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 20, 2022, an attacker executed a single transaction at approximately 02:51 UTC that drained approximately $600,000 from 29 user wallets. The vulnerability resided in LI.FI's pre-bridge swap feature, which allowed users to pass arbitrary calldata to any external contract address. Because the swap logic ran in the context of the LI.FI smart contract, and users had granted that contract infinite token approvals, the attacker was able to invoke transferFrom() on affected token contracts, moving funds directly out of user wallets. Tokens stolen included USDC, USDT, DAI, MATIC, RPL, GNO, AAVE, MVI, AUDIO, and JRT. The team disabled all swap methods upon discovering the exploit and published a post-mortem on the official blog. Of the 29 affected wallets, 25 were reimbursed from treasury for losses totaling approximately $80,000; the remaining four wallets (which held a combined $517,000) were offered compensation in the form of LiFi angel-investor token allocations rather than direct cash repayment.","heading":"March 2022 Exploit — $600,000 Approval Drain","sources":[{"url":"https://blog.li.fi/20th-march-the-exploit-e9e1c5c03eb9","name":"blog.li.fi","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/hacker-drained-600k-worth-of-crypto-from-li-finance/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://crypto.news/li-finance-defi-protocol-600k-reimburse/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 16, 2024, the LI.FI protocol suffered a second, substantially larger exploit in which approximately $11.6 million was drained from 153 wallets on Ethereum and Arbitrum. Assets stolen were exclusively stablecoins: USDC, USDT, and DAI. The exploit was traced to a newly deployed smart contract facet called GasZipFacet, which had been added to the live diamond proxy contract approximately five days before the attack. The vulnerable function, depositToGasZipERC20(), passed user-controlled _swapData directly to LibSwap.swap without validating the target contract address or calldata against a whitelist — a validation step that was present in all other existing facets but was omitted in GasZipFacet due to what LI.FI attributed to 'individual human error in overseeing the deployment process.' Security firm Decurity identified the root cause as 'a possibility of an arbitrary call with user controlled data.' PeckShield publicly noted the exploit was 'basically the same' as the 2022 incident, writing: 'The bug is basically the same. Are we learning anything from the past lesson(s)?' The attack only affected users who had manually set infinite token approvals; finite approvals — the default in LI.FI's own API, SDK, and widget — were not at risk. LI.FI disabled the vulnerable facet across all chains shortly after detection and advised users to revoke approvals immediately.","heading":"July 2024 Exploit — $11.6 Million Approval Drain","sources":[{"url":"https://li.fi/knowledge-hub/incident-report-16th-july/","name":"li.fi","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/07/16/defi-protocol-lifi-struck-by-8m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://cybersecuritynews.com/li-fi-protocol-hack/","name":"cybersecuritynews.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/lifi-smart-contract-hack/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","credibility":3}],"severity":"medium"},{"content":"Both the 2022 and 2024 exploits share the same structural root cause: arbitrary external calls executed from within the LI.FI smart contract in the context of a user's granted approval. In both cases, the attack vector involved passing user-controlled calldata to low-level contract calls without adequate validation of the destination address or function selector. Security researchers from PeckShield characterized the 2024 event as 'basically the same bug,' indicating that the post-mortem remediation following the 2022 incident was either incomplete or did not extend to newly deployed contract facets. The 2024 incident occurred despite LI.FI having raised a $17.5 million Series A in May 2023, which could have funded additional security infrastructure and process improvements. The use of a diamond proxy (EIP-2535) architecture introduces ongoing deployment risk, as each new facet must independently satisfy all security invariants that apply to the broader contract. The team acknowledged that the 2024 event stemmed from a lapse in deployment review procedures.","heading":"Repeated Vulnerability Pattern and Security Concerns","sources":[{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://medium.com/@gr_gred/li-fi-exploits-explained-the-same-mistake-twice-b46b1b9b4610","name":"medium.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/lifi-protocol-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/li-fi-hack-analysis-521388128d22/","name":"blog.solidityscan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the March 2022 exploit, LI.FI reimbursed 25 of 29 affected wallets from treasury, covering losses of approximately $80,000. The four remaining wallets, representing roughly $517,000 in losses, were offered LiFi angel-investor token allocations in lieu of direct cash compensation — a resolution that some affected users may have found inadequate given the illiquidity of unvested token grants. Following the July 2024 exploit, LI.FI announced a voluntary compensation plan with the backing of its major investors, committing to fully compensate all 153 affected wallets. The protocol set up a registration form for affected users and stated it was 'evaluating options to fully compensate affected users as soon as possible.' Binance Square reported that LI.FI initiated a voluntary compensation plan in late July 2024. The protocol engaged law enforcement and industry security partners to trace the stolen funds. In both incidents the team moved quickly to contain the exploit by disabling the vulnerable functionality.","heading":"User Compensation and Incident Response","sources":[{"url":"https://crypto.news/li-finance-defi-protocol-600k-reimburse/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2024-07-23-li-fi-initiates-voluntary-compensation-plan-after-hack-11182507343826","name":"binance.com","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/incident-report-16th-july/","name":"li.fi","type":"other","credibility":3},{"url":"https://cryptonews.com/news/lifi-protocol-releases-post-mortem-report-on-recent-11-6-million-hack/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"LI.FI was founded in 2021 by Philipp Zentner, who serves as CEO. The company is headquartered in Germany and has raised a total of approximately $51.7 million across multiple rounds. A $17.5 million Series A was closed in May 2023, co-led by CoinFund and Superscrypt. In December 2025, the company announced a $29 million Series A extension led by Multicoin Capital and CoinFund, with additional participation from L1D, Circle, and Factor[e] Ventures. The funding will support expansion into AI agent infrastructure, stablecoin payments, and an intent-based solver marketplace. As of late 2025 the protocol reported monthly transaction volume growth of 595% year-over-year, from $1.15 billion in October 2024 to $8 billion in October 2025.","heading":"Funding and Corporate Background","sources":[{"url":"https://www.prnewswire.com/news-releases/lifi-secures-29m-in-series-a-extension-led-by-multicoin-and-coinfund-to-scale-the-universal-liquidity-market-for-digital-assets-302639425.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.ypog.law/en/press/ypog-advises-li.fi-on-17.5-million-series-a-financing-round","name":"ypog.law","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/li-finance-fbae","name":"crunchbase.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Both historical exploits exclusively affected users who had granted infinite (unlimited) token approvals to the LI.FI smart contract. Users who relied on the default finite approval settings within LI.FI's API, SDK, or widget were not impacted in either incident. Security tools such as Revoke.cash have published dedicated pages for both the 2022 and 2024 LI.FI exploits, allowing affected addresses to check exposure and revoke remaining approvals. Users interacting directly with LI.FI contracts — particularly those who grant infinite approvals — should be aware of the protocol's exploitation history and consider revoking approvals after use. The protocol's diamond proxy architecture means new facets may be added at any time, and each carries inherent deployment risk.","heading":"User Risk Guidance","sources":[{"url":"https://revoke.cash/exploits/lifi","name":"revoke.cash","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","credibility":3},{"url":"https://x.com/lifiprotocol/status/1813207291778215955","name":"x.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"LI.FI (formerly Li.Finance) founded by Philipp Zentner to provide cross-chain bridge and DEX aggregation infrastructure.","source":"","date_original":"2021-01-01"},{"date":"2022-03-20","event":"First exploit: attacker drains approximately $600,000 from 29 user wallets via an arbitrary-call vulnerability in the pre-bridge swap feature. Team disables swap methods and begins post-mortem.","source":""},{"date":"2022-03-21","event":"LI.FI publishes post-mortem blog post on the March 2022 exploit and announces partial reimbursement plan.","source":""},{"date":"2023-05","event":"LI.FI closes $17.5 million Series A funding round co-led by CoinFund and Superscrypt.","source":"","date_original":"2023-05-01"},{"date":"2024-07-11","event":"GasZipFacet smart contract facet deployed to the LI.FI diamond proxy — approximately five days before the second exploit.","source":""},{"date":"2024-07-16","event":"Second exploit: attacker exploits missing whitelist validation in GasZipFacet's depositToGasZipERC20() function, draining approximately $11.6 million from 153 wallets across Ethereum and Arbitrum. LI.FI disables the vulnerable facet and issues emergency warning.","source":""},{"date":"2024-07-16","event":"PeckShield publicly states the 2024 bug is 'basically the same' as the 2022 exploit.","source":""},{"date":"2024-07-19","event":"LI.FI publishes Security Incident Report for the July 16 exploit, attributing the vulnerability to 'individual human error in overseeing the deployment process.'","source":""},{"date":"2024-07-23","event":"LI.FI initiates voluntary compensation plan for all 153 affected wallets, backed by major investors.","source":""},{"date":"2025-12-11","event":"LI.FI raises $29 million Series A extension led by Multicoin Capital and CoinFund, bringing total capital raised to approximately $51.7 million.","source":""}],"sources_used":[{"url":"https://li.fi/","name":"li.fi","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/li-fi-secures-usd29m-in-series-a-extension-led-by-multicoin-and-coinfund-to/","name":"li.fi","type":"other","credibility":3},{"url":"https://stablecoininsider.org/lifi-cross-chain-aggregator-2026/","name":"stablecoininsider.org","type":"other","credibility":3},{"url":"https://blog.li.fi/20th-march-the-exploit-e9e1c5c03eb9","name":"blog.li.fi","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/li-finance-protocol-loses-600-000-in-latest-defi-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/hacker-drained-600k-worth-of-crypto-from-li-finance/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://crypto.news/li-finance-defi-protocol-600k-reimburse/","name":"crypto.news","type":"other","credibility":3},{"url":"https://li.fi/knowledge-hub/incident-report-16th-july/","name":"li.fi","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2024/07/16/defi-protocol-lifi-struck-by-8m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/9ad65-lifi-protocol-loses-10m-in-second-hack","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://cybersecuritynews.com/li-fi-protocol-hack/","name":"cybersecuritynews.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/lifi-smart-contract-hack/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi-2024","name":"revoke.cash","type":"other","credibility":3},{"url":"https://medium.com/@gr_gred/li-fi-exploits-explained-the-same-mistake-twice-b46b1b9b4610","name":"medium.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/lifi-protocol-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/li-fi-hack-analysis-521388128d22/","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2024-07-23-li-fi-initiates-voluntary-compensation-plan-after-hack-11182507343826","name":"binance.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/lifi-protocol-releases-post-mortem-report-on-recent-11-6-million-hack/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://www.prnewswire.com/news-releases/lifi-secures-29m-in-series-a-extension-led-by-multicoin-and-coinfund-to-scale-the-universal-liquidity-market-for-digital-assets-302639425.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/12/11/cross-chain-liquidity-protocol-li-fi-raises-usd29m-in-series-a-extension","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.ypog.law/en/press/ypog-advises-li.fi-on-17.5-million-series-a-financing-round","name":"ypog.law","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/li-finance-fbae","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/lifi","name":"revoke.cash","type":"other","credibility":3},{"url":"https://x.com/lifiprotocol/status/1813207291778215955","name":"x.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T19:10:20.745592+00:00","updated_at":"2026-08-29T01:34:23.039+00:00"}}