LI.FI 2022 approval-drain exploit
An unchecked external-call path in LI.FI's pre-bridge swap logic allowed an attacker to invoke token contracts and drain assets from wallets that had granted infinite approvals.
Incident facts
- Incident title
- LI.FI 2022 approval-drain exploit
- Bridge
- LI.FI
- Incident date
- 2022-03-20
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum
- Affected assets
- USDC, USDT, DAI, MATIC, Unknown
- Attack category
- Cross Chain Contract Exploit
- Reported loss
- Approximately $600,000
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- None
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Full
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-29
- Last verified
- 2026-07-29
Amount and valuation
LI.FI's official postmortem reported approximately USD 600,000 stolen from 29 wallets, later valued at USD 587,500 or 205 ETH in the same report.
The affected basket included additional tokens represented as unknown in the current reference dictionary.
tokens drained from 29 wallets and converted to approximately 205 ETHapproximately USD 600,000
Canonical amount from the first-party postmortem; the same report later valued the assets at USD 587,500.
Timeline events
LI.FI approval-drain exploit occurred2022-03-20
An unchecked external call in pre-bridge swap logic drained tokens from 29 Ethereum wallets with infinite approvals.
Vulnerability patched and all affected wallets reimbursed2022-03-21
LI.FI deployed a whitelist-based fix, reenabled swaps, disabled infinite approvals by default, and reported that all 29 affected wallets were reimbursed for a total of USD 570,000.
LI.FI offered four larger affected users an angel-investment arrangement; one accepted it partially, and the official postmortem still reports all 29 wallets reimbursed.
LI.FI completed reimbursement for all affected wallets2022-03-21
LI.FI's first-party postmortem reported that all 29 affected wallets were reimbursed after the March 2022 approval-drain exploit, with USD 570,000 in total operator-funded compensation.
Discrete reimbursement milestone split from the semantically overloaded reopen event; operator-funded reimbursement remains separate from attacker-fund recovery.
Evidence records
- Knownsec Blockchain Lab | Li.Finance attack incidentKnownsec Blockchain Lab · Tier 1 · High reliability · secondary · 2022-03-21Claim scope: Incident Case
Independent technical reconstruction describing approximately 204 ETH taken and protocol compensation/redeployment.
- Li Finance protocol loses $600,000 in latest DeFi exploitCointelegraph · Tier 2 · Medium reliability · secondary · 2022-03-21Claim scope: Reimbursement
Contemporaneous report for 29 affected wallets, approximately $600,000 loss, patching, and the split reimbursement approach.
- LI.FI Attack: a Cross-chain Bridge Vulnerability? No, It’s Due to Unchecked External Call!BlockSec · Tier 1 · High reliability · secondary · 2022-03-21Claim scope: Incident Case
Independent root-cause analysis of the unchecked external-call path.
- Li Finance protocol loses $600,000 in latest DeFi exploitCointelegraph · Tier 2 · Medium reliability · secondary · 2022-03-21Claim scope: Incident Case
Event-scoped duplicate of bir_src_000058: contemporaneous reporting supports the LI.FI 2022 drain, affected-wallet count, amount, patching, and reimbursement split.
- Knownsec Blockchain Lab | Li.Finance attack incidentKnownsec Blockchain Lab · Tier 1 · High reliability · secondary · 2022-03-21Claim scope: Restart
Event-scoped duplicate of bir_src_000057: Knownsec's technical reconstruction supports redeployment, protocol restoration, and compensation handling.
- LI.FI Smart Contract Vulnerability Post MortemLI.FI · Tier 1 · High reliability · primary · 2022-03-21Claim scope: Incident Case
First-party postmortem supporting the unchecked external-call root cause, 29 affected wallets, approximately USD 600,000 stolen, and immediate swap-method containment.
- LI.FI Smart Contract Vulnerability Post MortemLI.FI · Tier 1 · High reliability · primary · 2022-03-21Claim scope: Reimbursement
Event-scoped duplicate supporting the deployed whitelist fix, swaps reenabled, 29 of 29 wallets reimbursed, and USD 570,000 total compensation.
- LI.FI Smart Contract Vulnerability Post MortemLI.FI · Tier 1 · High reliability · primary · 2022-03-21Claim scope: Reimbursement
Event-scoped first-party copy of bir_src_000265 supporting the discrete completed-reimbursement milestone: 29 of 29 affected wallets reimbursed and USD 570,000 total operator-funded compensation.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The attacker-held funds were not reported recovered in the reviewed first-party postmortem; user reimbursement was operator-funded.
- The postmortem states that one of four larger affected users partially accepted an angel-investment arrangement while all 29 wallets were reimbursed.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.