Fun

Li.Fi releases incident report following $11M hack

News Feed - 2024-07-19 04:07:26

Vince Quill4 hours agoLi.Fi releases incident report following $11M hackThe team also announced it was working on a voluntary compensation plan to reimburse 100% of funds to users affected by the exploit.492 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksFollowing the $11.6 million exploit of the Li.Fi protocol, an API used to bridge and swap digital assets across blockchains, the Li.Fi team released an update outlining the technical details of the breach.


According to the security update, the deployment of a new smart contract facet was ground zero forthe malicious attack. A vulnerability in the code allowed users calling the smart contract to initiate calls to any contract without prior validation.


This function is a result of code taken from the LibSwap library, used to facilitate calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.


Normally, these calls are screened against whitelisted addresses to ensure validation. However, Li.Fi explained that human error in deploying the offending smart contract facet was the root cause of the vulnerability exploited by the malicious actor.


The Li.Fi team confirmed the attack occurred on the Ethereum and Arbitrum networks and affected 156 wallets with the “infinite approvals” option turned on. Users without this option turned on were not affected by the exploit.Source: Li.Fi protocol


In statements to Cointelegraph, spokespeople for Li.Fi said they contained the exploit, addressed the critical vulnerability, and contacted the proper law enforcement authorities to trace stolen funds. At the time of this writing, the issue has been fixed, and Li.Fi is operating normally.


Related: Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBTNot the first time


In March 2022, Li.Fi was hit by a similar exploit affecting users with the “infinite approval” option turned on. The hackers drained $600,000 from the protocol from 29 wallets before the vulnerability was addressed.


The protocol was quick to reimburse investors for their losses, refunding 24 wallets directly from its treasury and offering the remaining five wallets a voluntary compensation plan akin to that received by early angel investors of Li.Fi.Crypto hacks put the damper on the industry in 2024


Unfortunately, hacks and exploits continue to plague the crypto industry and the decentralized financial sector, in particular.A chart comparing 2022-2024 losses from crypto hacks. Source: TRM.


According to a recent report from security firm Cyvers, 2024 losses from crypto exploits are nearing $1.4 billion, driven primarily by phishing attacks, and have risen sharply since 2023.


Magazine: Best and worst countries for crypto taxes — plus crypto tax tips# Blockchain# Business# Security# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

Kazakhstan President Demands ‘Urgent’ Regulation of Crypto Mining Amid Power Shortages
Kazakhstan President Demands ‘Urgent’ Regulation of Crypto Mining Amid Power Shortages Facing an electricity deficit largely blamed on cryptocurrency miners, Kazakhstan is tryi
25% of US Adults Plan to Start Investing in Crypto, Survey Shows
25% of US Adults Plan to Start Investing in Crypto, Survey Shows A U.S. consumer survey shows that 25% of respondents who currently do not own cryptocurrency plan to start investin
Casper Network halts operations following security breach
Amaka Nwaokocha13 hours agoCasper Network halts operations following security breachThis incident serves as a reminder of the ever-present need for vigilance and proactive measures in the rapidly evolving world of blockc
State-Owned Swiss Bank Postfinance to Offer Clients Direct Access to Crypto Market
State-Owned Swiss Bank Postfinance to Offer Clients Direct Access to Crypto Market Swiss post office’s banking unit, the state-owned Postfinance, is reportedly preparing to
Dogwifhat open interest declines 28% amid fears of a $1.50 'likely retest'
Ciaran Lyons2 hours agoDogwifhat open interest declines 28% amid fears of a $1.50 "likely retest"Crypto traders claim that Dogwifhat will "likely retest" the critical support level as its price and open interes
Gemini launches campaign finance initiative for pro-crypto candidates
Vince Quill1 hour agoGemini launches campaign finance initiative for pro-crypto candidatesThe announcement from Gemini followed $2 million in personal donations from the Winklevoss brothers to former President Trump"s re
Bitcoin mining will thrive under a Trump administration — MARA CEO
Vince Quill5 hours agoBitcoin mining will thrive under a Trump administration — MARA CEOMarathon CEO Fred Thiel said he would not comment on Harris’ policies because they are still unknown at this time.910 Total view
The Rapid Rise of IXFI Exchange – Now the World’s Biggest Buy Crypto Platform
The Rapid Rise of IXFI Exchange - Now the World’s Biggest Buy Crypto Platform press release PRESS RELEASE.Zurich, Switzerland, April 1st, 2023 – Since its launch at the end
WisdomTree wins NYDFS trust company charter
Zoltan Vardai12 hours agoWisdomTree wins NYDFS trust company charterThe charter will enable WisdomTree’s newly founded entity to offer crypto custody, stablecoin issuance, and stablecoin reserve management services.823
The 50th Anniversary of ‘Nixon Shock:’ How Suspending the Dollar’s Convertibility With Gold Fueled Today’s Fiat World
The 50th Anniversary of ‘Nixon Shock:’ How Suspending the Dollar’s Convertibility With Gold Fueled Today’s Fiat World Approximately 50 years ago today, A
Brazilian Crypto Investment Platform Bluebenx Stops Withdrawals Under Hack Allegations
Brazilian Crypto Investment Platform Bluebenx Stops Withdrawals Under Hack Allegations Bluebenx, a Brazil-based cryptocurrency investment platform, suspended withdrawals last week
Grayscale’s Bitcoin ETF records lowest outflows since conversion
Ana Paula Pereira4 hours agoGrayscale’s Bitcoin ETF records lowest outflows since conversionGrayscale’s GBTC posted $44.2 million in withdrawals on Feb. 23, marking its lowest daily volume since transitioning to an E