LI.FI hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 16, 2024 |
| Target type | Cross-chain bridge |
| Loss | $11,600,000Published estimates range $8,000,000 to $11,600,000Price at time of incident |
| Method | Access control flawA newly deployed facet of LI.FI's diamond-pattern contract, GasZipFacet, lacked the whitelist validation applied to every other facet. Its depositToGasZipERC20 function let a caller pass arbitrary calldata that the contract then executed, so the contract could be directed to transfer tokens out of any address that had granted it an unlimited (infinite) ERC-20 approval. |
| Chains | Ethereum, Arbitrum |
| Outcome | Users reimbursed |
What happened
LI.FI, a cross-chain bridging and liquidity aggregator whose contracts also power the Jumper Exchange front end, was exploited on 16 July 2024. The attack targeted GasZipFacet, a module added to LI.FI's diamond contract five days earlier to let users top up gas on destination chains.
The facet's depositToGasZipERC20 function allowed a caller to make arbitrary calls with user-controlled data, without the whitelist checks present in every other facet. Security firm Decurity, whose finding CoinDesk cited on the day, identified this arbitrary-call path as the root cause. Anyone could therefore instruct the contract to pull tokens from any address holding an unlimited ERC-20 approval to it. Wallets using the finite approvals set by default by LI.FI's API, SDK and widget were not exposed. USDC, USDT and DAI were taken on Ethereum and Arbitrum.
The figures moved during the day. CoinDesk first reported roughly $8 million, then noted the project had revised the total to about $11 million. LI.FI's own incident report, published two days later, put the loss at about $11.6 million across 153 affected wallets, and that is the figure recorded here as the affected party's own accounting; Cointelegraph and Crypto Briefing both carried $11.6 million, though Cointelegraph counted 156 wallets rather than 153.
LI.FI disabled the vulnerable facet across all chains within hours and attributed its deployment to individual human error in overseeing the release process. It announced a voluntary compensation plan, backed by its investors, to reimburse 100 percent of affected users' funds. Cointelegraph noted that a March 2022 incident had similarly affected only wallets with infinite approvals enabled, costing about $600,000 across 29 wallets, which LI.FI also reimbursed.
Sources
- LI.FIPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Official post-mortem: https://li.fi/knowledge-hub/incident-report-16th-july
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "LI.FI hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/li-fihttps://itokenly.com/hacks/li-fiPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.