Fun

Li​.Fi protocol attacked, $10M drained

News Feed - 2024-07-16 10:07:49

Josh O"Sullivan10 hours agoLi​.Fi protocol attacked, $10M drainedThe Li.Fi protocol experienced a security breach when hackers exploited a specific contract address, resulting in the loss of over $8 million in cryptocurrencies. The attack has since been mitigated.125571 Total views167 Total sharesListen to article 0:00Breaking newsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate (July 16, 16:20 UTC): This article has been updated to reflect that the attack on Li.Fi has since been mitigated, and the protocol was functioning normally. 


Li.Fi, an API for Ethereum Virtual Machine and Solana swaps and bridging, was attacked on July 16, and over $10 million in cryptocurrencies was drained. 


According to Cyvers, the team’s systems alerted to suspicious transactions on Li.Fi involving a specific contract address.


Cyvers recommended users revoke their approvals for the suspected address: 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae


Speaking with Cointelegraph, Meir Dolev, co-founder and chief technology officer at Cyvers, explained that protocols must be vigilant:“Hackers can exploit these approvals to drain both assets stored in the contracts and funds in the connected wallets of users.”Source: Cyvers


Related: Filipino artists hacked to promote XRP scamLi.Fi warning


In an X post on July 16, Li.Fi warned its community that users should not interact with Li.Fi-powered applications until further notice.


When the attack was underway, the team explained that it was investigating the exploit and clarified that users who “did not set infinite approval” were not at risk.


For users who manually set infinite approvals, the Li.Fi team stated that the following addresses should be revoked:0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae0x341e94069f53234fE6DabeF707aD4248305257150xDE1E598b81620773454588B85D6b5D4eEC32573e0x24ca98fB6972F5eE05f0dB00595c7f68D9FaFd68


At 11:44 am ET (15:44 UTC), Li.Fi updated its users in an X post that the smart contract vulnerability had been mitigated. “There is currently no further risk to users,” the post stated. “The only wallets affected were set to infinite approvals, and represented only a very small number of users."


Related:Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBT$10 million drained


According to Cyvers, approximately $10 million in cryptocurrency holdings were drained, which also affected the Arbitrum blockchain.


Dolev told Cointelegraph that “this incident underscores the risks inherent in granting wallet approvals to smart contracts.”


In an X post updating the community on the situation, Cyvers again recommended users revoke the 0x1231deb6f5749ef6ce6943a275a1d3e7486f4eae address to prevent further losses.


Related:Dough Finance loses $1.8M in flash loan attackFrom drains to flash loan attacks


Decentralized finance protocol Dough Finance was also recently under attack on July 12, becoming the victim of a $1.8 million flash loan attack.


Cyvers reported on the incident, explaining that the attacker funded the attack through the zero-knowledge protocol Railgun and swapped the stolen USD Coin (USDC) for Ether (ETH).


According to Web3 security provider Olympix, the exploit, which accrued 608 ETH and is valued at around $1.8 million, resulted from unvalidated call data with the “ConnectorDeleverageParaswap.”


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Cryptocurrencies# Hackers# Tokens# Hacks# DeFiAdd reaction

News Feed

Jesse Coghlan7 hours agoCrypto custodian Prime Trust files for Chapter 11 bankruptcyThe crypto custodian’s bankruptcy comes as it’s been unable to honor customer withdrawals for months.3798 Total views22 Total shares
Nigerian Central Bank Stops Forex Sales to Bureaus de Change — Operators Accused of Feeding Black Market
Nigerian Central Bank Stops Forex Sales to Bureaus de Change — Operators Accused of Feeding Black Market The Central Bank of Nigeria (CBN) recently announced t
14th Anniversary of Bitcoin’s Genesis Block: A Look Back at the Birth of Cryptocurrency
14th Anniversary of Bitcoin"s Genesis Block: A Look Back at the Birth of Cryptocurrency 14 years ago on Jan. 3, 2009, Satoshi Nakamoto launched the Bitcoin network and block zero a
Derek Andersen2 hours agoDigital rupee gets big usability boost through Yes Bank integration with UPIThe Yes Bank app’s UPI integration is the first for the Indian retail CBDC, which has seen a variety of projects sinc
Roaring Kitty swipes 6.6% of Chewy, clarifies he is ‘Not a Cat’
Josh O"Sullivan12 hours agoRoaring Kitty swipes 6.6% of Chewy, clarifies he is ‘Not a Cat’Keith Gill, known for his role in the GameStop saga, surprises the market with a significant stake in Chewy.2892 Total views11
Bitcoin on edge as economy falters: 10x Research report
Josh O"Sullivan14 hours agoBitcoin on edge as economy falters: 10x Research reportFindings from a 10x Research report reveal a potential Bitcoin price drop below $50,000 amid US economic uncertainty, impacting the broade
‘Buy Bitcoin’ sign that photobombed Janet Yellen sells for $1M
Jesse Coghlan3 hours ago‘Buy Bitcoin’ sign that photobombed Janet Yellen sells for $1MThe original scrawled sign was auctioned off by “Bitcoin Sign Guy” Christian Langalis for 16 BTC after apparently sitting in h
PayPal opens PYUSD stablecoin to USD conversions for cross-border transfers
Zhiyuan Sun8 hours agoPayPal opens PYUSD stablecoin to USD conversions for cross-border transfersThe cross-border payments will be handled via PayPal’s Xoom subsidiary.1248 Total views4 Total sharesListen to article 0:
Amaka Nwaokocha15 hours agoCurve Finance vows to reimburse users after $62M hackThe platform said it would assess each impacted user for reimbursement.3891 Total views33 Total sharesListen to article 0:00NewsJoin us on s
Curve mulls dropping TUSD as crvUSD backing after SEC charges
Alex O’Donnell5 hours agoCurve mulls dropping TUSD as crvUSD backing after SEC chargesThe regulator alleged TUSD was 99% backed by a risky offshore fund, raising concerns about using TUSD to back Curve"s stablecoin.151
GBTC fees will drop when Bitcoin ETFs ‘start to mature’ — Grayscale CEO
Jesse Coghlan7 hours agoGBTC fees will drop when Bitcoin ETFs ‘start to mature’ — Grayscale CEOGrayscale’s Bitcoin ETF may have the highest fees and outflows compared to the competition, but chief Michael Sonnens
Pancakeswap Launches Version 3 of Protocol on BNB and Ethereum Blockchains
Pancakeswap Launches Version 3 of Protocol on BNB and Ethereum Blockchains On Monday, April 3, the decentralized exchange (dex) platform Pancakeswap launched version 3 of its proto