LI.FI 2024 facet approval exploit
A newly deployed smart-contract facet omitted validation around arbitrary external calls, allowing an attacker to drain assets from 153 Ethereum and Arbitrum wallets with infinite approvals.
Incident facts
- Incident title
- LI.FI 2024 facet approval exploit
- Bridge
- LI.FI
- Incident date
- 2024-07-16
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, Arbitrum
- Affected assets
- USDC, USDT, DAI
- Attack category
- Cross Chain Contract Exploit
- Reported loss
- Approximately $11.6 million
- Amount confidence
- High
- Loss amount basis
- Official Incident Report Prioritized
- Recovery
- Unknown
- Reimbursement
- Announced
- Restart
- Unknown
- Current outcome
- Active After Incident
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
LI.FI's official incident report estimated approximately $11.6 million stolen; initial contemporaneous reporting described roughly $11 million.
The official post-incident estimate is used as canonical.
assets drained from 153 walletsapproximately $11.6 million
Canonical amount.
initial public estimateroughly $11 million
Retained as the initial estimate.
Why this remains unresolved
- The final recovered amount and completion of compensation are not established in this seed record.
Timeline events
LI.FI facet exploit disclosed and contained2024-07-16
LI.FI disabled a newly deployed vulnerable facet after unauthorized withdrawals from wallets with infinite approvals on Ethereum and Arbitrum.
Security incident report and compensation review published2024-07-18
LI.FI attributed the vulnerability to a missing validation check introduced through human deployment error and said full-compensation options were being evaluated.
The official report establishes containment, not the exact service-restoration point.
Evidence records
- Security Incident Report 16th JulyLI.FI · Tier 1 · High reliability · primary · 2024-07-18Claim scope: Incident Case
Primary incident report for the $11.6 million estimate, 153 wallets, missing validation check, containment, and compensation review.
- Defi Protocol LI.FI Struck by $11M ExploitCoinDesk · Tier 2 · High reliability · secondary · 2024-07-16Claim scope: Amount
Contemporaneous reporting for initial loss estimates, containment, and user-risk scope.
- Security Incident Report 16th JulyLI.FI · Tier 1 · High reliability · primary · 2024-07-18Claim scope: Incident Case
Event-scoped duplicate of bir_src_000060: LI.FI's official report supports the 2024 exploit mechanism, affected wallets, amount, containment, and compensation review.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Later reimbursement completion requires a dedicated source review.
- The final law-enforcement and asset-tracing outcome is unknown.
- The exact incident-era service-restoration point is not established in the reviewed corpus.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.