Lixir Finance Hack

Reported loss $12K
Ethereum
Broken EIP-2612 Permit Verification

What happened

On June 25, 2026, Lixir Finance's Ethereum vault-token contracts were exploited for approximately $12,300 through a broken EIP-2612 permit path that enabled unauthorized withdrawals of underlying assets.

Technical root cause

Lixir's permit implementation did not correctly validate the recovered signer against the owner or bind the signature to the owner's nonce and deadline. A forged signature could therefore create unauthorized allowances for an attacker-controlled spender.

How it happened

The attacker reused a dummy or forged permit signature to set approvals on multiple holders' vault-token balances, then called withdrawFrom and withdrawETHFrom-style paths to move WETH, USDC, USDT, and LIX to attacker-controlled contracts.

Protocol details

Classification Protocol Logic
Protocol Type Liquidity Manager
Implementation language Solidity
Protocol links @lixirfinance

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.