LI.FI Hack
What happened
LI.FI's pre-bridge swap feature allowed an attacker to drain tokens from wallets that had granted its router unlimited spending approvals. The team disabled swaps, fixed the vulnerable call path, and reported reimbursing all affected wallets.
The swap router allowed unrestricted external calls. Attacker-supplied transferFrom payloads therefore ran with the router as spender and could consume token allowances granted by other users.
How it happened
- The router accepted an array of arbitrary contract addresses and calldata.
- The attacker supplied a small valid swap followed by calls to token contracts.
- Those calls invoked transferFrom using allowances that users had granted to the LI.FI router, moving tokens from their wallets to the attacker.
- The small swap satisfied the output check, allowing the transaction to complete.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.