Fun

Li​.Fi protocol attacked, $10M drained

News Feed - 2024-07-16 10:07:49

Josh O"Sullivan10 hours agoLi​.Fi protocol attacked, $10M drainedThe Li.Fi protocol experienced a security breach when hackers exploited a specific contract address, resulting in the loss of over $8 million in cryptocurrencies. The attack has since been mitigated.125571 Total views167 Total sharesListen to article 0:00Breaking newsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate (July 16, 16:20 UTC): This article has been updated to reflect that the attack on Li.Fi has since been mitigated, and the protocol was functioning normally. 


Li.Fi, an API for Ethereum Virtual Machine and Solana swaps and bridging, was attacked on July 16, and over $10 million in cryptocurrencies was drained. 


According to Cyvers, the team’s systems alerted to suspicious transactions on Li.Fi involving a specific contract address.


Cyvers recommended users revoke their approvals for the suspected address: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae


Speaking with Cointelegraph, Meir Dolev, co-founder and chief technology officer at Cyvers, explained that protocols must be vigilant:“Hackers can exploit these approvals to drain both assets stored in the contracts and funds in the connected wallets of users.”Source: Cyvers


Related: Filipino artists hacked to promote XRP scamLi.Fi warning


In an X post on July 16, Li.Fi warned its community that users should not interact with Li.Fi-powered applications until further notice.


When the attack was underway, the team explained that it was investigating the exploit and clarified that users who “did not set infinite approval” were not at risk.


For users who manually set infinite approvals, the Li.Fi team stated that the following addresses should be revoked:0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae0x341e94069f53234fE6DabeF707aD4248305257150xDE1E598b81620773454588B85D6b5D4eEC32573e0x24ca98fB6972F5eE05f0dB00595c7f68D9FaFd68


At 11:44 am ET (15:44 UTC), Li.Fi updated its users in an X post that the smart contract vulnerability had been mitigated. “There is currently no further risk to users,” the post stated. “The only wallets affected were set to infinite approvals, and represented only a very small number of users."


Related:Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT$10 million drained


According to Cyvers, approximately $10 million in cryptocurrency holdings were drained, which also affected the Arbitrum blockchain.


Dolev told Cointelegraph that “this incident underscores the risks inherent in granting wallet approvals to smart contracts.”


In an X post updating the community on the situation, Cyvers again recommended users revoke the 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae address to prevent further losses.


Related:Dough Finance loses $1.8M in flash loan attackFrom drains to flash loan attacks


Decentralized finance protocol Dough Finance was also recently under attack on July 12, becoming the victim of a $1.8 million flash loan attack.


Cyvers reported on the incident, explaining that the attacker funded the attack through the zero-knowledge protocol Railgun and swapped the stolen USD Coin (USDC) for Ether (ETH).


According to Web3 security provider Olympix, the exploit, which accrued 608 ETH and is valued at around $1.8 million, resulted from unvalidated call data with the “ConnectorDeleverageParaswap.”


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Cryptocurrencies# Hackers# Tokens# Hacks# DeFiAdd reaction

News Feed

Coinbase global adviser to join President Biden’s reelection campaign
Turner Wright3 hours agoCoinbase global adviser to join President Biden’s reelection campaignIt’s unclear whether Keisha Lance Bottoms will advise the campaign on crypto, but she spoke about digital assets in Atlanta
Ukraine President Zelensky Returns Law ‘On Virtual Assets’ to Parliament
Ukraine President Zelensky Returns Law ‘On Virtual Assets’ to Parliament The Ukrainian president has sent the recently adopted law “On Virtual Assets” back to the
Eric Hughes: A Cypherpunk’s Manifesto
Eric Hughes: A Cypherpunk"s ManifestoPrivacy is necessary for an open society in the electronic age. Privacy is not secrecy. A private matter is something one doesn’t want the
Tom Blackstone7 hours agoCircle launches ‘bridged USDC standard’ for deploying to new networksCircle published a new standard that allows developers to launch an unofficial bridged version of USDC that can later beco
Bitcoin Dominance Sliding Below This Level Could Signal Start Of Altseason, Trading Firm Says
Este artículo también está disponible en español. Bitcoin (BTC) continues its historic price trajectory, trading in the low $90,000 range at the time of writing. However,
For the 1st Time, All ERC20 Tokens Can Be Lent and Borrowed With UniLend’s Upcoming Version 2
For the 1st Time, All ERC20 Tokens Can Be Lent and Borrowed With UniLend"s Upcoming Version 2 press release PRESS RELEASE. UniLend Finance published their protocol update blog intro
Gareth Jenkinson10 hours agoPerfect storm for undervalued ASICs: Blockstream plans $50M raise to buy minersBlockstream intends to buy and store ASIC mining hardware ahead of Bitcoin’s halving in 2024.2762 Total views14
Bitcoin Price Outlook for July — Traders Remain Concerned About Upcoming Fed Rate Hike and Bankrupt Crypto Firms
Bitcoin Price Outlook for July — Traders Remain Concerned About Upcoming Fed Rate Hike and Bankrupt Crypto Firms During the first week of July, bitcoin prices have risen to their
Bitcoin And Crypto Market To Crash? Analyst’s August-September Prediction
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
‘XRP Is The End Game’ — Pundit Reveals Why It’s Better Than Bitcoin
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Australia tries again to combat ‘future sectors’ crypto scams
Arijit Sarkar2 hours agoAustralia tries again to combat ‘future sectors’ crypto scamsThe “Proposed Scams Code Framework” consultation paper aims to delegate clear roles and responsibilities to government and priv
Gareth Jenkinson14 hours agoBorneo authorities seize illegal crypto miners running off stolen powerA Malaysian energy supplier uncovered an illegal cryptocurrency mining operation stealing power from the local grid on th