Li Finance protocol loses $600,000 in latest DeFi exploit

Li Finance protocol loses $600,000 in latest DeFi exploit

The Li Finance swap aggregator has experienced a smart contract exploit leading to the loss of around $600,000 from 29 users’ wallets.

The exploit took place at 2:51 am UTC on March 20. The attacker was able to extract varying amounts of 10 different tokens from wallets that had given “infinite approval” to the Li Finance protocol. Among the stolen tokens were USD Coin (USDC), Polygon (MATIC), Rocket Pool (RPL), Gnosis (GNO), Tether (USDT), Metaverse Index (MVI), Audius (AUDIO), AAVE (AAVE), Jarvis Reward Token (JRT), and DAI (DAI).

Our top trading bots

When the team learned about the exploit 12 hours later at 2:15 pm UTC, it shut down all swapping functions on the platform in order to prevent any further losses.

By 2:50 am UTC on March 21, the team had issued a post mortem detailing the events of the exploit. The team said that the attacker swapped the stolen tokens for a total of about 205 Ether (ETH) valued at roughly $600,000. At the time of writing, the stolen ETH had yet to be moved from the attacker’s wallet. LiFi also assured users that the bug has been identified and patched.

Of the 29 wallets that were hit in this attack, 25 have been reimbursed from treasury funds for their losses. Those 25 wallets only accounted for $80,000, or 13% of the total value lost. The owners of the remaining four wallets that lost a combined $517,000 have been contacted and offered a deal to compensate them by honoring their losses as angel investors in the protocol.

They would receive LiFi tokens under the same terms as other angel investors in an amount equal to their losses from each wallet. This would also help to mitigate the damage to the platform’s treasury.

The hacker was also contacted and offered a bug bounty to return the funds.

Li Finance protocol loses $600,000 in latest DeFi exploit
The Li Finance team reached out to offer a bug bounty to a hacker.

The attack appears to have come at an unfortunate time. Li Finance CEO Philipp Zentner told Cointelegraph on March 21 that “We’re literally a week away from our audit,” adding that “we have multiple companies auditing us.”

However, even a thorough audit of the code may not have picked up this particular bug, according to a researcher “Transmissions11” at crypto investment firm Paradigm. He explained in a March 21 tweet that the error in Li Finance’s code is easy to miss and “subtle if you’re not in the right mindset.”

Li Finance protocol loses $600,000 in latest DeFi exploit

Related: ‘Unlucky:’ Agave and Hundred Finance DeFi protocols exploited for $11M

This latest hack in the decentralized finance (DeFi) sector demonstrates how giving infinite approvals to smart contracts opens a user’s funds to a greater amount of risk. Infinite approvals allow users to swap coins at a decentralized exchange (DEX) an unlimited amount of times without needing to approve any more transactions.

Continue reading at Cointelegraph
Colorado accepts tax payments in crypto: Was it just a matter of time?
The governor of Colorado, Jared Polis, announced in February that the state government plans to allow residents to pay taxes in cryptocurrencies as early...
Decentralized technology will end the Web3 privacy conundrum
Although the modern internet connects us like never before, one thing that younger generations have never truly experienced is the feeling of genuine privacy....
The biggest winners and losers of the crypto industry in 2021
The cryptocurrency and blockchain industry experienced explosive growth in 2021, particularly in its decentralized finance (DeFi) and nonfungible token...
Blockchains vie for NFT market, but Ethereum still dominates — Report
This month, Cointelegraph Research will release a comprehensive report on nonfungible tokens, discussing NFTs in detail and providing a detailed guide to...
Futures-based Bitcoin ETF has '75% chance of approval' in October — analyst
A Bitcoin (BTC) exchange-traded fund (ETF) has a 75% chance of being approved this month — in some form.In comments this weekend, Eric Balchunas, senior...
Blockchain streaming platform Audius announces Solana NFT integration
Blockchain-based music streaming platform Audius announced Thursday that it had launched full Solana NFT integration, allowing its more than six million...
TP ICAP to launch Bitcoin exchange with Fidelity, Standard Chartered
Major global interdealer broker TP ICAP is launching a cryptocurrency trading platform with Fidelity Investments and British banking giant Standard Chartered.TP...
Cointelegraph Consulting: DeFi hit by a tsunami of liquidations in May
The savage sell-off that took place in mid-May fueled volatility in markets and triggered liquidations among numerous decentralized finance protocols. Like...
Ethereum Could Soon Steal Bitcoin's Thunder as Inflationary Hedge
By Yasin EbrahimInvesting.com – Ethereum is still well below its May highs, but a hotly anticipated update expected in the coming weeks could pit it against...
Jamaica's central bank taps Irish tech outfit for CBDC project
Jamaica is the latest country making concrete efforts towards issuing its own sovereign digital currency.According to a press release by the Bank of Jamaica...
EOS Falls 13% In Rout
Investing.com - EOS was trading at $3.5571 by 18:20 (22:20 GMT) on the Investing.com Index on Wednesday, down 13.21% on the day. It was the largest one-day...
Vitalik Buterin: NFTs can be a social good, not just a casino for rich celebrities
Ethereum co-creator Vitalik Buterin believes NFTs can be applied to socially relevant causes such as charities and funding public goods, but not while the...
Most of Stolen 500 Million NEM Coins Already Laundered – Report
The most substantial part of 500 million NEM units, stolen by hackers from Japanese cyber money trading venue Coincheck around two months ago, has already...
Cryptocurrency Lovers Will Spend More Electricity Than All of Argentina
In 2018, the need for electricity for all miners in the world may exceed energy consumption in Argentina.This opinion was expressed by analysts of financial...
Altcoin to Invest: Golem
Golem Network (GNT) is a decentralized computer network. Golem is almost like any other blockchain project that has tokens. Its value is $0,21 although...