Fun

Li​.Fi protocol attacked, $10M drained

News Feed - 2024-07-16 10:07:49

Josh O"Sullivan10 hours agoLi​.Fi protocol attacked, $10M drainedThe Li.Fi protocol experienced a security breach when hackers exploited a specific contract address, resulting in the loss of over $8 million in cryptocurrencies. The attack has since been mitigated.125571 Total views167 Total sharesListen to article 0:00Breaking newsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate (July 16, 16:20 UTC): This article has been updated to reflect that the attack on Li.Fi has since been mitigated, and the protocol was functioning normally. 


Li.Fi, an API for Ethereum Virtual Machine and Solana swaps and bridging, was attacked on July 16, and over $10 million in cryptocurrencies was drained. 


According to Cyvers, the team’s systems alerted to suspicious transactions on Li.Fi involving a specific contract address.


Cyvers recommended users revoke their approvals for the suspected address: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae


Speaking with Cointelegraph, Meir Dolev, co-founder and chief technology officer at Cyvers, explained that protocols must be vigilant:“Hackers can exploit these approvals to drain both assets stored in the contracts and funds in the connected wallets of users.”Source: Cyvers


Related: Filipino artists hacked to promote XRP scamLi.Fi warning


In an X post on July 16, Li.Fi warned its community that users should not interact with Li.Fi-powered applications until further notice.


When the attack was underway, the team explained that it was investigating the exploit and clarified that users who “did not set infinite approval” were not at risk.


For users who manually set infinite approvals, the Li.Fi team stated that the following addresses should be revoked:0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae0x341e94069f53234fE6DabeF707aD4248305257150xDE1E598b81620773454588B85D6b5D4eEC32573e0x24ca98fB6972F5eE05f0dB00595c7f68D9FaFd68


At 11:44 am ET (15:44 UTC), Li.Fi updated its users in an X post that the smart contract vulnerability had been mitigated. “There is currently no further risk to users,” the post stated. “The only wallets affected were set to infinite approvals, and represented only a very small number of users."


Related:Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT$10 million drained


According to Cyvers, approximately $10 million in cryptocurrency holdings were drained, which also affected the Arbitrum blockchain.


Dolev told Cointelegraph that “this incident underscores the risks inherent in granting wallet approvals to smart contracts.”


In an X post updating the community on the situation, Cyvers again recommended users revoke the 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae address to prevent further losses.


Related:Dough Finance loses $1.8M in flash loan attackFrom drains to flash loan attacks


Decentralized finance protocol Dough Finance was also recently under attack on July 12, becoming the victim of a $1.8 million flash loan attack.


Cyvers reported on the incident, explaining that the attacker funded the attack through the zero-knowledge protocol Railgun and swapped the stolen USD Coin (USDC) for Ether (ETH).


According to Web3 security provider Olympix, the exploit, which accrued 608 ETH and is valued at around $1.8 million, resulted from unvalidated call data with the “ConnectorDeleverageParaswap.”


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Cryptocurrencies# Hackers# Tokens# Hacks# DeFiAdd reaction

News Feed

National Bank of Kazakhstan Publishes Whitepaper for Digital Tenge
National Bank of Kazakhstan Publishes Whitepaper for Digital Tenge The central bank of Kazakhstan has completed the second phase of testing for its digital currency and published a
David Attlee30 minutes agoSolana becomes ecosystem partner of Dubai free zoneThe Solana Foundation has become an ecosystem partner for the Dubai Multi Commodities Centre, one of the free economic zones within the UAE.447
Gareth Jenkinson12 hours agoTether authorizes $1B USDT to ‘replenish’ Tron networkBlockchain trackers flag $1-billion “authorised but not issued” USDT mint at Tether’s Treasury; CTO Paolo Ardoino clarifies hold
Arijit Sarkar13 hours agoSingapore introduces 5 new pilots to test asset tokenizationThe latest initiatives by the Monetary Authority of Singapore aim to develop foundational capabilities to scale tokenized markets.2936
Unicoin exec explains why projects fail — Blockchain Futurist Conference
Vince Quill4 hours agoUnicoin exec explains why projects fail — Blockchain Futurist ConferenceUnicoin hopes to launch on exchanges later this year and focuses on creating digital assets backed by investment portfolio w
Bitcoin Unlimited Launches Two-Option Voting App Powered by Bitcoin Cash
Bitcoin Unlimited Launches Two-Option Voting App Powered by Bitcoin CashOn September 16, the Bitcoin Unlimited development team launched a new application called Votepeer. The softw
Cornell Professor Warns of Disruption to US Bond Market From Potential Collapse of Major Stablecoin
Cornell Professor Warns of Disruption to US Bond Market From Potential Collapse of Major Stablecoin A professor from Cornell University has warned about the potential effects a col
Price analysis 8/5: SPX, DXY, BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA
Rakesh Upadhyay6 hours agoPrice analysis 8/5: SPX, DXY, BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADAGlobal equity markets witnessed a massive sell-off, pulling Bitcoin and several major cryptocurrencies to unexpected lows.280
Bank of Italy to release crypto guidelines in ‘coming days’ — Governor
Jesse Coghlan3 hours agoBank of Italy to release crypto guidelines in ‘coming days’ — GovernorItaly’s central bank will soon share how the country should apply the EU’s MiCA crypto laws, with its governor slamm
Amaka Nwaokocha1 hour agoGoogle to protect users in AI copyright accusationsGoogle explicitly stated that only seven products fall under this legal protection, excluding Google’s Bard search tool.484 Total views3 Total
Valkyrie Files for ETF That Invests in Firms That Derive 50% Revenue From Bitcoin Mining Industry
Valkyrie Files for ETF That Invests in Firms That Derive 50% Revenue From Bitcoin Mining Industry The digital currency asset manager Valkyrie has applied for an exchange-traded fun
OpenAI co-founder and chief scientist departs AI firm
Jesse Coghlan7 hours agoOpenAI co-founder and chief scientist departs AI firmIllya Sutskever said he’s leaving OpenAI for a “personally meaningful” project with research director Jakub Pachocki now moving into the