T
iTokenly

LI.FI hack — July 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 16, 2024
Target typeCross-chain bridge
Loss$11,600,000Published estimates range $8,000,000 to $11,600,000Price at time of incident
MethodAccess control flawA newly deployed facet of LI.FI's diamond-pattern contract, GasZipFacet, lacked the whitelist validation applied to every other facet. Its depositToGasZipERC20 function let a caller pass arbitrary calldata that the contract then executed, so the contract could be directed to transfer tokens out of any address that had granted it an unlimited (infinite) ERC-20 approval.
ChainsEthereum, Arbitrum
OutcomeUsers reimbursed

What happened

LI.FI, a cross-chain bridging and liquidity aggregator whose contracts also power the Jumper Exchange front end, was exploited on 16 July 2024. The attack targeted GasZipFacet, a module added to LI.FI's diamond contract five days earlier to let users top up gas on destination chains.

The facet's depositToGasZipERC20 function allowed a caller to make arbitrary calls with user-controlled data, without the whitelist checks present in every other facet. Security firm Decurity, whose finding CoinDesk cited on the day, identified this arbitrary-call path as the root cause. Anyone could therefore instruct the contract to pull tokens from any address holding an unlimited ERC-20 approval to it. Wallets using the finite approvals set by default by LI.FI's API, SDK and widget were not exposed. USDC, USDT and DAI were taken on Ethereum and Arbitrum.

The figures moved during the day. CoinDesk first reported roughly $8 million, then noted the project had revised the total to about $11 million. LI.FI's own incident report, published two days later, put the loss at about $11.6 million across 153 affected wallets, and that is the figure recorded here as the affected party's own accounting; Cointelegraph and Crypto Briefing both carried $11.6 million, though Cointelegraph counted 156 wallets rather than 153.

LI.FI disabled the vulnerable facet across all chains within hours and attributed its deployment to individual human error in overseeing the release process. It announced a voluntary compensation plan, backed by its investors, to reimburse 100 percent of affected users' funds. Cointelegraph noted that a March 2022 incident had similarly affected only wallets with infinite approvals enabled, costing about $600,000 across 29 wallets, which LI.FI also reimbursed.

Sources

  1. LI.FIPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. Crypto BriefingSecondary · retrieved 2026-08-01
  4. CointelegraphSecondary · retrieved 2026-08-01

Official post-mortem: https://li.fi/knowledge-hub/incident-report-16th-july

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "LI.FI hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/li-fi
https://itokenly.com/hacks/li-fi

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.