Lixir Finance Hack
What happened
On June 25, 2026, Lixir Finance's Ethereum vault-token contracts were exploited for approximately $12,300 through a broken EIP-2612 permit path that enabled unauthorized withdrawals of underlying assets.
Lixir's permit implementation did not correctly validate the recovered signer against the owner or bind the signature to the owner's nonce and deadline. A forged signature could therefore create unauthorized allowances for an attacker-controlled spender.
How it happened
The attacker reused a dummy or forged permit signature to set approvals on multiple holders' vault-token balances, then called withdrawFrom and withdrawETHFrom-style paths to move WETH, USDC, USDT, and LIX to attacker-controlled contracts.
Protocol details
Security review history
- HAECHI Audit View report
- CertiK View report
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.