Incident case

LI.FI 2022 approval-drain exploit

An unchecked external-call path in LI.FI's pre-bridge swap logic allowed an attacker to invoke token contracts and drain assets from wallets that had granted infinite approvals.

reviewedcurrent

Incident facts

Incident title
LI.FI 2022 approval-drain exploit
Bridge
LI.FI
Incident date
2022-03-20
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDC, USDT, DAI, MATIC, Unknown
Attack category
Cross Chain Contract Exploit
Reported loss
Approximately $600,000
Recovery
None
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Resolution
Final outcome known
Last reviewed
2026-07-29
Last verified
2026-07-29

Timeline events

  • LI.FI approval-drain exploit occurred2022-03-20

    An unchecked external call in pre-bridge swap logic drained tokens from 29 Ethereum wallets with infinite approvals.

    Exploit DisclosedHigh
  • Vulnerability patched and all affected wallets reimbursed2022-03-21

    LI.FI deployed a whitelist-based fix, reenabled swaps, disabled infinite approvals by default, and reported that all 29 affected wallets were reimbursed for a total of USD 570,000.

    Bridge ReopenedHigh

Evidence records

Known unknowns