Incident case

LI.FI 2024 facet approval exploit

A newly deployed smart-contract facet omitted validation around arbitrary external calls, allowing an attacker to drain assets from 153 Ethereum and Arbitrum wallets with infinite approvals.

reviewedcurrent

Incident facts

Incident title
LI.FI 2024 facet approval exploit
Bridge
LI.FI
Incident date
2024-07-16
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, Arbitrum
Affected assets
USDC, USDT, DAI
Attack category
Cross Chain Contract Exploit
Reported loss
Approximately $11.6 million
Amount confidence
High
Loss amount basis
Official Incident Report Prioritized
Recovery
Unknown
Reimbursement
Announced
Restart
Unknown
Current outcome
Active After Incident
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

LI.FI's official incident report estimated approximately $11.6 million stolen; initial contemporaneous reporting described roughly $11 million.

The official post-incident estimate is used as canonical.

Why this remains unresolved

Timeline events

  • LI.FI facet exploit disclosed and contained2024-07-16

    LI.FI disabled a newly deployed vulnerable facet after unauthorized withdrawals from wallets with infinite approvals on Ethereum and Arbitrum.

    Exploit DisclosedHigh
  • Security incident report and compensation review published2024-07-18

    LI.FI attributed the vulnerability to a missing validation check introduced through human deployment error and said full-compensation options were being evaluated.

    Incident Report PublishedHigh

    The official report establishes containment, not the exact service-restoration point.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.