Incident case

LI.FI 2022 approval-drain exploit

An unchecked external-call path in LI.FI's pre-bridge swap logic allowed an attacker to invoke token contracts and drain assets from wallets that had granted infinite approvals.

reviewedcurrent

Incident facts

Incident title
LI.FI 2022 approval-drain exploit
Bridge
LI.FI
Incident date
2022-03-20
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDC, USDT, DAI, MATIC, Unknown
Attack category
Cross Chain Contract Exploit
Reported loss
Approximately $600,000
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
None
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Full
Resolution
Final outcome known
Last reviewed
2026-07-29
Last verified
2026-07-29

Amount and valuation

LI.FI's official postmortem reported approximately USD 600,000 stolen from 29 wallets, later valued at USD 587,500 or 205 ETH in the same report.

The affected basket included additional tokens represented as unknown in the current reference dictionary.

Timeline events

  • LI.FI approval-drain exploit occurred2022-03-20

    An unchecked external call in pre-bridge swap logic drained tokens from 29 Ethereum wallets with infinite approvals.

    Exploit DisclosedHigh
  • Vulnerability patched and all affected wallets reimbursed2022-03-21

    LI.FI deployed a whitelist-based fix, reenabled swaps, disabled infinite approvals by default, and reported that all 29 affected wallets were reimbursed for a total of USD 570,000.

    Bridge ReopenedHigh

    LI.FI offered four larger affected users an angel-investment arrangement; one accepted it partially, and the official postmortem still reports all 29 wallets reimbursed.

  • LI.FI completed reimbursement for all affected wallets2022-03-21

    LI.FI's first-party postmortem reported that all 29 affected wallets were reimbursed after the March 2022 approval-drain exploit, with USD 570,000 in total operator-funded compensation.

    Reimbursement CompletedHigh

    Discrete reimbursement milestone split from the semantically overloaded reopen event; operator-funded reimbursement remains separate from attacker-fund recovery.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.