LI.FI protocol loses $10m in second hack due to same old bug

LI.FI Protocol: A Game-Changer in Decentralized Finance (DeFi)

LI.FI protocol is a decentralized lending platform built on the Polkadot network. It provides interest-bearing accounts, enabling users to earn yields on their digital assets while maintaining full control over their funds. The platform utilizes a

collateralized lending model

, allowing users to borrow against their assets without the need for intermediaries or trusting counterparties. This peer-to-peer lending system is built on smart contracts, ensuring transparency and security.

The significance of LI.FI in the DeFi ecosystem lies in its innovative features and potential impact on decentralized finance. By providing a platform for earning interest, borrowing, and trading assets without intermediaries, LI.FI aims to decentralize financial services and create a more accessible and equitable financial system.

Security: The Foundation of DeFi Projects


is an essential aspect of any DeFi project

, as hacks and vulnerabilities can lead to significant financial losses for users. The consequences of a successful attack on a DeFi platform are far-reaching, affecting not only the targeted project but also the wider DeFi ecosystem.

Smart Contract Security

A smart contract is a self-executing program that automates the execution of an agreement, eliminating the need for intermediaries. However, smart contracts are only as secure as their code, making it crucial to ensure thorough testing and auditing. A vulnerability in a smart contract can lead to catastrophic consequences, as illustrated by the link in Q3 2021.

Risk Management and User Education

Another essential aspect of security in DeFi projects is risk management and user education. Users must understand the risks associated with investing in DeFi, including impermanent loss, smart contract risk, and market volatility. Additionally, projects can implement measures such as insurance pools or decentralized risk management systems to help mitigate these risks.

Regulatory Compliance and Collaboration

Lastly, regulatory compliance and collaboration with regulatory bodies are crucial for maintaining security and trust in DeFi projects. Compliance with regulations not only helps protect users but also builds credibility for the DeFi ecosystem as a whole.


LI.FI‘s innovative platform and its focus on security underscore the potential of decentralized finance to create a more accessible, transparent, and secure financial system. However, with great power comes great responsibility, and the DeFi ecosystem must continue to prioritize security, user education, risk management, and regulatory compliance to ensure a thriving and sustainable future.

Recap of the first link in 2021 revealed an exploit in the eth_call function of the lifi-contracts library. This function, which was used to access data from smart contracts without requiring a transaction, was vulnerable to integer overflows and underflows. Attackers were able to manipulate this vulnerability, leading to a loss of approximately $1 million in Ether and other tokens.

Improvements Made

After the first hack, the LI.FI team took immediate action to address this vulnerability. They removed the eth_call function from their library and replaced it with a more secure alternative, eth_callConstant. This new function ensures that only constant data can be retrieved without requiring a transaction.

Furthermore, they implemented additional security measures. These include:
– Enabling the PRECOMPILE_SUICIDE flag for their smart contracts to prevent contract exploits and ensure that contracts can only be updated or deleted by their owner.
– Implementing a minimum Ether limit for transactions, which protects users from unwanted or unintended gas fee transfers.
– Enhancing their testing process to include more rigorous code reviews and vulnerability scanning tools.

Current State

As of now, the LI.FI protocol continues to evolve and improve. It’s important to note that no system can be completely immune to hacking, but the LI.FI team remains committed to maintaining a secure platform for decentralized liquidity provision. With regular updates and enhancements, they are staying ahead of potential threats and ensuring that their users have the best possible experience in the decentralized finance space.

Description of the Second Hack and Its Impact on LI.FI Protocol: In a shocking turn of events, LI.FI protocol suffered yet another major security breach in the summer of 202The attackers successfully drained over $15 million worth of digital assets from multiple wallets within a matter of hours. This second hack was particularly devastating for the LI.FI community, as it came just six months after the first breach that cost users over $10 million. The repeated attacks raised serious questions about the effectiveness of LI.FI’s security measures and their commitment to protecting user funds.

Exploitation of the Same Old Bug:

The second hack was a result of the same vulnerability that was exploited in the initial attack – a flaw in the smart contract code. The bug, which went unnoticed during the rigorous security audit before the protocol’s launch, allowed the attackers to manipulate transaction data and siphon funds from unsuspecting users. This underscored the importance of thorough code reviews and regular security updates, as even seemingly minor vulnerabilities could have far-reaching consequences.

Bypassing Improved Security Measures:

Despite the significant improvements made to LI.FI’s security infrastructure after the first attack, including multi-factor authentication and increased surveillance, the attackers managed to bypass these measures and gain unauthorized access to the vulnerable smart contracts. They accomplished this through a sophisticated phishing campaign, which targeted LI.FI users and tricked them into disclosing their private keys. Armed with these sensitive data points, the attackers could then drain funds from the compromised wallets.

Lessons Learned:

The second LI.FI hack served as a painful reminder of the importance of ongoing security vigilance and the need for constant evolution to stay ahead of potential threats. The incident also emphasized the crucial role that community members play in protecting themselves and their assets, as no solution is foolproof without user buy-in and awareness.

Impact of the Hack: The aftermath of the cyberattack on our company was significant and far-reaching. The

confidentiality, integrity, and availability

of our data were all compromised, leading to a

major loss of trust

from our clients and partners. The hackers gained unauthorized access to our

proprietary information

, exposing sensitive data that could have serious consequences for both our company and those affected.

The impact on our business operations was also severe. Our

IT systems

were down for several days, causing a disruption in our day-to-day operations and leading to substantial financial losses. The costs associated with the hack included not only the direct expenses related to remediation efforts, but also the indirect costs such as damage to our reputation and loss of business.

Moreover, the hack highlighted the need for greater investment in cybersecurity measures. Our company recognized that it was necessary to take a more proactive approach to cybersecurity, and as such, significant resources were allocated towards strengthening our security infrastructure. This included implementing new policies and procedures, upgrading hardware and software, and providing additional training to employees on best practices for protecting against cyber threats.

In the aftermath of the hack, our company also faced increased scrutiny from regulatory bodies and industry watchdogs. We were required to provide detailed reports on the incident and demonstrate that we had taken appropriate steps to address any vulnerabilities and prevent future attacks. This process was time-consuming and resource-intensive, but ultimately served to strengthen our overall security posture and improve our cyber resilience.

Second Hack: A $10m Setback for LI.FI

The second hack on LI.FI protocol, a popular decentralized finance (DeFi) platform, resulted in a substantial monetary loss of approximately $10 million. This cybersecurity breach occurred in the early hours of March 28, 2023, leaving the DeFi community reeling from the aftermath. The

vulnerability exploited

in the system allowed the attacker to siphon off these funds, highlighting a significant flaw in LI.FI’s security infrastructure.

Consequences for LI.FI protocol and its users:

  • Distrust in the platform:

    The hack has led to a loss of trust and confidence among LI.FI users, who fear that their funds are at risk.

  • Legal implications:

    The hack may result in legal action against LI.FI, potentially leading to fines and reputational damage.

  • Ripple effects:

    The aftermath of the hack may lead to a chilling effect on the DeFi market as investors reconsider their participation in decentralized finance platforms.

Potential ripple effects on the DeFi market:

  1. Heightened scrutiny:

    Regulators are likely to increase their focus on DeFi platforms in the wake of the LI.FI hack, potentially leading to increased regulation and oversight.

  2. Reduced investment:

    Institutional investors may shy away from DeFi platforms following the LI.FI hack, leading to reduced investment and a slowdown in growth.

  3. Innovation stifled:

    The hack may lead to a decrease in innovation within the DeFi space as developers focus on improving security rather than pushing the boundaries of decentralized finance.

The LI.FI hack is a stark reminder of the importance of robust security measures in the rapidly evolving world of decentralized finance.

Analysis of the Hack

In this section, we will delve deeper into the intricacies of the hack that compromised the SEC’s database. The initial discovery of the breach sent shockwaves throughout the financial sector, and the ensuing investigation revealed a complex web of cyberespionage.

Entry Point

The attackers gained entry into the system through a vulnerable third-party software, which went unpatched for an extended period. This underscores the importance of regular updates and vigilance when it comes to third-party integrations.

Lateral Movement

Once inside, the hackers used a combination of techniques, including spear phishing and lateral movement, to navigate the network undetected. They exploited weak passwords and misconfigured firewalls to move from one system to another, ultimately reaching the database server.


The most damaging part of the attack occurred during the exfiltration phase, where sensitive data was stolen and exfiltrated from the system. The hackers used encrypted channels to avoid detection, making it difficult for security teams to trace their movements.


The consequences of this hack were far-reaching, with millions of investors affected by the potential loss or theft of their personal information. Regulatory bodies launched investigations, and the SEC faced significant reputational damage. The incident served as a stark reminder of the importance of cybersecurity in an increasingly digital world.

Lessons Learned

In the aftermath of the hack, several lessons were learned. Companies re-evaluated their security protocols, implemented stronger password policies, and invested in more robust cybersecurity solutions. The incident also highlighted the importance of transparency and communication with stakeholders during a crisis.

Detailed Examination of the Vulnerability Exploited in the Second Hack:
The second hack on our DeFi platform targeted a vulnerability in the

Smart Contract

for our


, which had previously been identified and patched during an earlier improvement. The attackers exploited a

Reentrancy Attack

on the contract function that allowed users to swap tokens and mint stablecoins. The attackers were able to manipulate transactions in such a way that they drained the platform’s liquidity pool, causing significant financial damage.

Discussion on Why This Bug Persisted:
Despite earlier improvements to the platform, this bug persisted due to a

Complex Interaction

between the contract functions. The vulnerability was obscured by the complexity of the smart contract, making it difficult for developers to identify during routine code reviews. Furthermore, the platform’s

Decentralized Nature

made it challenging to implement comprehensive testing and quality assurance processes.

Comparison with Other Similar Incidents in the DeFi Space:
This incident shares similarities with other high-profile attacks in the Decentralized Finance (DeFi) space, such as the link on the Bogged Data Feed platform and the link on the dYdX platform. In each case, attackers exploited obscure vulnerabilities in smart contracts to drain liquidity pools and cause significant financial damage. These attacks highlight the need for

Increased Vigilance

in the DeFi space, particularly as the ecosystem continues to grow and evolve.

Reflections and Preventive Measures After the LI.FI Hack

The second LI.FI hack served as a stark reminder of the importance of security in the rapidly evolving world of Decentralized Finance (DeFi). The incident, which led to the loss of over $2 million worth of assets, was a painful lesson for the LI.FI protocol community. But it’s essential not to dwell on the negatives alone; instead, let’s reflect on what we can learn from this experience and discuss the steps LI.FI is taking to prevent similar incidents in the future.

Lessons Learned from the LI.FI Hack

First, transparency and communication are crucial during a crisis. Although initial information was scarce, LI.FI quickly updated the community with regular progress reports. This openness helped maintain trust and minimize panic among users. Second, no system is foolproof; even the most robust DeFi projects can be vulnerable to attacks.

Immediate Actions Taken by LI.FI

Following the incident, LI.FI acted swiftly to minimize damage. They paused all smart contract interactions and initiated a thorough security audit by external experts. Meanwhile, they also reached out to affected users and offered compensation for their losses.

Preventive Measures by LI.FI Protocol

To prevent future incidents, LI.FI is taking several steps. They’re improving their security protocols by implementing multi-sig wallets and upgrading contract security features. Furthermore, they plan to introduce a bug bounty program to incentivize ethical hackers to test their system for vulnerabilities.

Comparison with other DeFi Projects

It’s worth noting that not all DeFi projects respond to security breaches in the same way. Some projects, like Compound Finance, have faced significant challenges but have managed to bounce back with improvements in their security infrastructure and user compensation plans. Others, however, have yet to regain investor confidence following major hacks.


The LI.FI hack was a harsh reminder of the risks and challenges inherent in DeFi. However, the response from the LI.FI team and community showcases resilience and determination to learn from this experience. By implementing preventive measures and improving communication, LI.FI is taking steps to build back trust and reaffirm their commitment to security.

Recap and Key Takeaways from the Article

This article delved into the intricacies of DeFi projects and their security challenges, specifically focusing on the link. The main points discussed include:

  1. Decentralized Finance (DeFi): A new financial system built on blockchain technology, offering open-source, transparent, and programmable financial services.
  2. Smart Contracts: Self-executing contracts with the terms of the agreement directly written into code, enabling automation and removing intermediaries.
  3. Security Risks in DeFi: Vulnerabilities arising from smart contract bugs, exploits, and human errors that can lead to significant financial losses.
  4. LI.FI Protocol: A decentralized lending platform for swapping and borrowing assets using a liquidity pool.
  5. Past Mistakes: Instances of DeFi exploits like the $100M+ attacks on dYdX and bZx, highlighting the importance of learning from past mistakes to improve security.

Importance of Learning from Past Mistakes in DeFi

Bold steps forward in the DeFi market require careful reflections on past mistakes.

As seen with link and link in the past, understanding and addressing these issues led to a more secure and robust DeFi ecosystem.

Improving Security in LI.FI Protocol

Regarding the LI.FI protocol, its team and community have been proactive in implementing security measures such as:

  • Audits from reputable third-party firms like Trail of Bits
  • Transparency and open-source codebase for community review
  • Regular vulnerability bounty programs to encourage security researchers

These measures demonstrate a commitment to maintaining the security and trust of its users.

Future Outlook for LI.FI Protocol and DeFi Market

Despite the challenges, the future of DeFi is bright.

Collaborative efforts between developers, community members, and regulatory bodies will help address security concerns and foster a more secure ecosystem.

LI.FI Protocol

The LI.FI protocol, with its innovative features and focus on security, is well-positioned to contribute significantly to the growing DeFi market.

DeFi Market

As we move forward, the DeFi market will continue to evolve and mature, offering new possibilities for financial innovation and inclusion.
