Saturday, October 10, 2026 Plain-English guides to how blockchain and crypto actually work AboutContact
Blockchain

DeFi Protocol Li.Fi Suffers $11 Million Cyberattack: What Happened

Li.Fi lost about $11 million in a cyberattack exploiting a smart-contract flaw. What happened and how to stay safe.

DeFi Protocol Li.Fi Suffers $11 Million Cyberattack: What Happened

In July 2024, the cross-chain bridge aggregator Li.Fi became the latest DeFi protocol to suffer a major exploit, losing roughly $11 million in user funds. The $11 million cyberattack targeted a vulnerability in one of the protocol’s smart contracts, allowing an attacker to drain tokens from user wallets that had previously granted the protocol spending approvals.

The incident was a stark reminder of one of DeFi’s most persistent risks: token approvals. The attack did not break private keys or compromise the Li.Fi frontend — it exploited the permissions users had granted to the protocol’s contracts, turning a convenience feature into an attack vector.

How the $11 Million Cyberattack Happened

Li.Fi routes swaps and bridge transfers across chains through modular smart contracts. Security researchers determined that the attacker exploited a flaw allowing arbitrary calls from a contract facet: essentially, the vulnerable contract could be tricked into executing attacker-chosen instructions, including calls that moved tokens out of user wallets.

The attack played out across Ethereum mainnet and Arbitrum. The attacker crafted transactions that invoked the vulnerable contract, which then called token contracts to transfer funds from wallets holding open approvals to Li.Fi’s contracts. Because those approvals were unlimited in many cases — a common default when users approve a DEX or bridge “once” — the attacker could take the full balance of approved tokens. Within a short window, around $11 million in various tokens, including stablecoins and ether, was siphoned off.

Which Funds Were at Risk

Crucially, only wallets that had granted token approvals to the affected Li.Fi contracts were exposed. Users who had never interacted with Li.Fi, or who had already revoked their approvals, were unaffected. This is the double-edged nature of the ERC-20 approval model: granting a protocol permission to move your tokens is what makes one-click swaps possible, but a vulnerability in the approved contract turns that permission into a loaded weapon.

The Li.Fi team moved quickly to contain the damage, pausing the affected contracts and urging users to revoke outstanding approvals through tools like Revoke.cash. They also engaged security firms to trace the stolen funds and offered communications to affected users.

Lessons From the Cyberattack

  • Revoke approvals you no longer need. Periodically audit your wallet’s token approvals on each chain you use and revoke anything stale. Unlimited approvals to protocols you rarely use are unnecessary risk.
  • Prefer limited approvals. When a dapp asks for unlimited spending permission, consider approving only the amount you intend to transact. Many wallets now support custom approval amounts.
  • Separate your wallets. Keep long-term holdings in a cold wallet that never touches DeFi protocols, and use a smaller “hot” wallet for bridging, swapping, and experimenting.
  • Use a hardware wallet for approvals. Even if a contract is exploited, a hardware wallet at least ensures no transaction can be signed without your physical confirmation — though it cannot protect funds already covered by an open approval.
  • Watch protocol announcements. Following a project’s official channels means you hear about pauses and revocation guidance within minutes, not days.

What Users Should Do After Any Bridge Exploit

  1. Check your approvals immediately. Use a revocation tool to see which contracts can move your tokens on every chain you have used.
  2. Revoke and re-approve narrowly. Remove broad approvals and, if you continue using the protocol after it relaunches safely, grant only what you need.
  3. Move untouched funds. If a wallet held approvals to a compromised contract, consider migrating remaining assets to a fresh address after revoking.
  4. Verify official guidance. Scammers swarm exploit news with fake “refund” sites. Only trust links from the protocol’s verified channels, and never enter a seed phrase anywhere.

Why Approvals Are DeFi’s Quiet Risk

The $11 million cyberattack worked because of a design trade-off most users never think about. Every time you “approve” a token on a decentralized app, you sign an on-chain permission letting that app’s contract move your tokens in the future. Wallets default to unlimited approvals because re-approving before every swap would be tedious — but that convenience means a single bug in the approved contract can empty your wallet, even months after your last transaction.

This is why security researchers treat open approvals like open tabs on a browser: harmless until one of them turns malicious. The Li.Fi incident was not the first approval-based exploit, and it will not be the last. Until wallets make granular, time-limited approvals the default, the responsibility falls on users to audit their permissions regularly — a chore, but a far cheaper one than the alternative.

The Bigger Picture for Bridge Security

The $11 million cyberattack on Li.Fi fits a painful pattern: bridges and aggregators, which must juggle complex cross-contract interactions, remain among DeFi’s most exploited categories. Each incident pushes the ecosystem toward better standards — stricter audit practices, more conservative approval UX in wallets, and contract architectures that minimize the blast radius of any single bug.

For users, the takeaway is practical rather than philosophical: approvals are permissions, permissions are risk, and managing them is part of using DeFi safely. The convenience of “approve once, swap forever” is real — but so is the cost when the contract on the other side turns out to be vulnerable.

Frequently Asked Questions

How do DeFi protocols get hacked?

Common causes include bugs in smart contract code, poorly validated inputs, compromised admin keys, and unlimited token approvals that let a vulnerable contract move users’ funds.

What are token approvals and why do they matter?

When you use a DeFi app you often approve a contract to spend your tokens. If you grant unlimited approval and that contract is later exploited, attackers can drain the approved tokens. Revoke approvals you no longer need using a reputable approval checker.

Can stolen DeFi funds be recovered?

Sometimes. Teams may negotiate with attackers, freeze stablecoins, or trace funds with analytics firms, but full recovery is uncommon. Prevention is far more reliable than recovery.

This article is for educational purposes only and is not financial advice. Crypto assets are volatile; do your own research before making decisions.

Blockchain Pulse Editorial

Our team writes original, plain-English explainers on blockchain technology and crypto, checked against primary sources. Read our editorial standards.