Fun

Li.Fi releases incident report following $11M hack

News Feed - 2024-07-19 04:07:26

Vince Quill13 hours agoLi.Fi releases incident report following $11M hackThe team also announced it was working on a voluntary compensation plan to reimburse 100% of funds to users affected by the exploit.848 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksFollowing the $11.6 million exploit of the Li.Fi protocol, an API used to bridge and swap digital assets across blockchains, the Li.Fi team released an update outlining the technical details of the breach.


According to the security update, the deployment of a new smart contract facet was ground zero forthe malicious attack. A vulnerability in the code allowed users calling the smart contract to initiate calls to any contract without prior validation.


This function is a result of code taken from the LibSwap library, used to facilitate calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.


Normally, these calls are screened against whitelisted addresses to ensure validation. However, Li.Fi explained that human error in deploying the offending smart contract facet was the root cause of the vulnerability exploited by the malicious actor.


The Li.Fi team confirmed the attack occurred on the Ethereum and Arbitrum networks and affected 156 wallets with the “infinite approvals” option turned on. Users without this option turned on were not affected by the exploit.Source: Li.Fi protocol


In statements to Cointelegraph, spokespeople for Li.Fi said they contained the exploit, addressed the critical vulnerability, and contacted the proper law enforcement authorities to trace stolen funds. At the time of this writing, the issue has been fixed, and Li.Fi is operating normally.


Related: Lazarus is moving millions from $305M DMM Bitcoin hack — ZachXBTNot the first time


In March 2022, Li.Fi was hit by a similar exploit affecting users with the “infinite approval” option turned on. The hackers drained $600,000 from the protocol from 29 wallets before the vulnerability was addressed.


The protocol was quick to reimburse investors for their losses, refunding 24 wallets directly from its treasury and offering the remaining five wallets a voluntary compensation plan akin to that received by early angel investors of Li.Fi.Crypto hacks put the damper on the industry in 2024


Unfortunately, hacks and exploits continue to plague the crypto industry and the decentralized financial sector, in particular.A chart comparing 2022-2024 losses from crypto hacks. Source: TRM.


According to a recent report from security firm Cyvers, 2024 losses from crypto exploits are nearing $1.4 billion, driven primarily by phishing attacks, and have risen sharply since 2023.


Magazine: Best and worst countries for crypto taxes — plus crypto tax tips# Blockchain# Business# Security# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

Tom Blackstone6 hours agoBase’s ‘Onchain Summer’ saw over 700K NFTs minted from 268K users in AugustThe “Onchain Summer” promotion drove activity to the new network, with hundreds of thousands of users minting
Tristan Greene6 hours agoUS Federal Reserve Banks say stablecoins could ‘become a source of financial instability’The report compares stablecoins to money market funds and ultimately concludes they have similar short
Ezra Reguerra13 hours agoBrad Garlinghouse jabs at maximalists: ‘It will be a multichain world’Ripple CEO Brad Garlinghouse discussed discouraging maximalists and factors that could drive further institutional adopti
Coinbase Confirms ‘No Financing Exposure’ to Bankrupt Crypto Firms Celsius, Voyager, Three Arrows Capital
Coinbase Confirms "No Financing Exposure" to Bankrupt Crypto Firms Celsius, Voyager, Three Arrows Capital Crypto exchange Coinbase has confirmed that the company “had no fin
Analyst Says Be Concerned About XRP Price When This Starts Happening To 3-Day Candles
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
2021 Bitcoin Price Predictions: Analysts Forecast BTC Values Will Range Between Zero to $600K
2021 Bitcoin Price Predictions: Analysts Forecast BTC Values Will Range Between Zero to $600K As bitcoin has touched new price highs on Thursday nearing the $50k
Regulated Bitcoin ETPs Skyrocket, Coinshares Cites ‘Unprecedented Interest from Institutional Investors’
Regulated Bitcoin ETPs Skyrocket, Coinshares Cites "Unprecedented Interest from Institutional Investors" The Sweden-based XBT provider Coinshares saw roughly $20
India Confirms ‘It’s Not Illegal to Buy or Sell Crypto’ — Government Will Consult Widely on Crypto Regulation
India Confirms "It"s Not Illegal to Buy or Sell Crypto" — Government Will Consult Widely on Crypto Regulation India’s finance secretary has confirmed that it is not illega
Bitcoin’s Hashrate Hits an All-Time High Nearing 300 Exahash per Second
Bitcoin"s Hashrate Hits an All-Time High Nearing 300 Exahash per Second While Bitcoin’s mining difficulty was expected to decrease two days ago on June 8, instead the diffic
Binance drops Bitcoin Ordinals, medical tourism in the metaverse: Nifty Newsletter
Ezra Reguerra5 hours agoBinance drops Bitcoin Ordinals, medical tourism in the metaverse: Nifty NewsletterBinance said it was dropping support for Bitcoin Ordinals as part of its efforts to streamline product offerings.1
If Bitcoin Passes $14K, Analysts Say Traders ‘Should Look to $20,000’ Instead of Looking Back
If Bitcoin Passes $14K, Analysts Say Traders "Should Look to $20,000" Instead of Looking Back While bitcoin prices touched all-time 2020 highs on Tuesday, a few
US Lawmakers Accuse Gary Gensler of ‘Hypocritical Mismanagement of SEC’ — Say the Chairman ‘Refuses to Practice What He Preaches’
US Lawmakers Accuse Gary Gensler of "Hypocritical Mismanagement of SEC" — Say the Chairman "Refuses to Practice What He Preaches" Four congressmen have accused the U.S. Securitie