Li.Fi releases incident report following $11M hack
The team also announced it was working on a voluntary compensation plan to reimburse 100% of funds to users affected by the exploit.
Following the $11.6 million exploit of the Li.Fi protocol, an API used to bridge and swap digital assets across blockchains, the Li.Fi team released an update outlining the technical details of the breach.
According to the security update, the deployment of a new smart contract facet was ground zero for the malicious attack. A vulnerability in the code allowed users calling the smart contract to initiate calls to any contract without prior validation.
This function is a result of code taken from the LibSwap library, used to facilitate calls between decentralized exchanges, service providers, and clients to coordinate the asset bridging and swapping processes.
Go to Source
Author: Vince Quill
Related posts:
- Uranium Finance developer suspected of ‘leaking’ information leading to $50M exploit
- DeFi-ing exploits: New Chainalysis tool tracks stolen crypto across multiple chains
- Gnosis launches Hashi bridge aggregator to help prevent hacks
- Two key security practices for Web3 startups from Israel Crypto Conference