LI.FI Hack

Reported loss $600K
Ethereum
Token Approval Abuse

What happened

LI.FI's pre-bridge swap feature allowed an attacker to drain tokens from wallets that had granted its router unlimited spending approvals. The team disabled swaps, fixed the vulnerable call path, and reported reimbursing all affected wallets.

Technical root cause

The swap router allowed unrestricted external calls. Attacker-supplied transferFrom payloads therefore ran with the router as spender and could consume token allowances granted by other users.

How it happened

  1. The router accepted an array of arbitrary contract addresses and calldata.
  2. The attacker supplied a small valid swap followed by calls to token contracts.
  3. Those calls invoked transferFrom using allowances that users had granted to the LI.FI router, moving tokens from their wallets to the attacker.
  4. The small swap satisfied the output check, allowing the transaction to complete.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.