LI.FI; Reviewed & Scored | The Block Note
DEX Aggregator Review · Updated August 2026

LI.FI:
the infrastructure behind countless wallets, carrying a real, repeated vulnerability pattern.

We tore apart LI.FI, a cross-chain liquidity aggregation and routing layer embedded inside a large number of wallets and DeFi apps, across the same aggregator-adapted scorecard we've used throughout this series. From genuinely broad reach across 60+ blockchain networks spanning EVM chains, Solana, Bitcoin, and other alt-VMs, a comprehensive product suite combining bridges, DEXs, and intent-based solvers behind one integration, and a genuinely transparent, detailed public incident report, to a real, genuinely concerning finding worth centering directly: on July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets, and at least one detailed, credible security firm described this as nearly identical to a prior exploit in 2022, a real, repeated vulnerability pattern within the same underlying architecture. We found a well-corroborated, important distinction: the exploit was confirmed limited to wallets using infinite token approvals, with finite approvals, LI.FI's own default setting, unaffected; and landed on a score the marketing page won't show you.

Type Cross-Chain Liquidity Aggregation Infrastructure Platforms API/SDK/Widget · 60+ chains (EVM, Solana, Bitcoin, alt-VMs) Fees ~0.25% default; integrator-tunable Discount Offer None
li.fi
Infrastructure
60+ chains · Embedded in many wallets
2022 + 2024: a repeated vulnerability pattern

Our take, up front: LI.FI is genuinely different from most platforms we've reviewed in this aggregator series: rather than a single consumer app, it's a routing and orchestration layer, embedded via API, SDK, and widget inside a large number of wallets and DeFi apps, connecting users to bridges, DEXs, and intent-based solvers across a single integration. Real, genuinely broad reach across 60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, among the broadest chain coverage claims we've found in this entire series. Real, genuinely extensive product suite built for embedding: same-chain swaps, cross-chain swaps, contract calls, multi-step flows, status tracking, intent-based execution, and newer workflow tools like Composer and Deposit. Real, disclosed audits from named firms including Code4rena and Quantstamp. Real, honest, notable absence of a publicly traded token as of early 2026, alongside a real, disclosed, proactive warning that any token claiming LI.FI affiliation on third-party exchanges should be treated with suspicion. What we can't set aside: a real, genuinely concerning finding. On July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets on Ethereum and Arbitrum; critically, at least one detailed, credible security firm described this as nearly identical to a prior exploit in 2022, a real, repeated vulnerability pattern within the same underlying Diamond Pattern architecture. Real, genuinely important, well-corroborated distinction: the exploit was confirmed limited specifically to wallets using infinite token approvals; finite approvals, the default setting in LI.FI's own API, SDK, and widget, were not affected. Real, genuinely positive, disclosed incident response: the vulnerable facet was disabled across all chains immediately, and a full, detailed, technical incident report was published directly. Real, disclosed default protocol fee around 0.25%, though genuinely "integrator-tunable," meaning the actual fee a user pays depends on which specific app or wallet embeds LI.FI. We weighted all of it below.

Real, genuinely important, well-corroborated two-incident history: a July 2024 exploit ($11.6 million, per LI.FI's own detailed incident report, affecting 153 wallets on Ethereum and Arbitrum) via an arbitrary-call vulnerability in a newly-deployed contract facet, and at least one detailed, credible technical source describing this as nearly identical to a prior 2022 exploit, a genuinely concerning, real repeated vulnerability pattern. Real, genuinely important, well-corroborated distinction: the exploit was confirmed limited specifically to wallets using infinite token approvals; finite approvals, the default setting in LI.FI's own API, SDK, and widget, were not affected. Real, genuinely positive, disclosed incident response: the vulnerable facet was disabled across all chains immediately, and a full, detailed, technical incident report was published. Real, disclosed audits from named firms including Code4rena and Quantstamp.

Why this scores below the midpoint: a genuinely transparent, detailed incident response and a well-corroborated distinction isolating the exploit to a specific, non-default configuration are real positives, tempered by a genuinely concerning, repeated (2022 and 2024) vulnerability pattern within the same underlying architecture.

Pros

  • Full, detailed, technical incident report published directly; vulnerable facet disabled immediately
  • Finite approvals (the default) confirmed unaffected in the 2024 incident
  • Disclosed audits from named firms (Code4rena, Quantstamp)

Cons

  • Jul 2024: $11.6M exploit via a newly-deployed facet, affecting 153 wallets
  • At least one credible source describes this as nearly identical to a 2022 exploit

Real, genuinely broad, well-documented aggregation combining bridges, DEXs, and intent-based solvers behind a single integration, tapping liquidity from major sources including Uniswap, 1inch, Stargate, and Across. Real, genuinely distinctive infrastructure positioning: rather than a single consumer app, LI.FI is the routing layer embedded inside a large number of wallets and DeFi apps.

Why this scores well: genuinely broad, comprehensive aggregation and a real, distinctive infrastructure role that most consumer-facing competitors don't occupy.

Pros

  • Comprehensive aggregation combining bridges, DEXs, and intent-based solvers
  • Embedded infrastructure role across many wallets and apps

Cons

  • Actual routing quality experienced depends partly on which integrator's configuration you use

Real, genuinely non-custodial. Real, honest, notable absence of a publicly traded token as of early 2026, alongside a real, important disclosed warning that any token claiming LI.FI affiliation on third-party exchanges should be treated with suspicion.

Why this scores above the midpoint: genuinely non-custodial architecture and an honest, proactive scam warning are real positives.

Pros

  • Genuinely non-custodial; proactive, disclosed warning against fake affiliated tokens

Cons

  • No publicly traded token means no direct, disclosed governance mechanism for users to weigh

Real, genuinely broad reach across 60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, a genuinely wide scope even relative to other broad aggregators in this series.

Why this scores among the highest categories on this review: genuinely among the broadest chain coverage claims we've found in this entire aggregator series.

Pros

  • 60+ chains including EVM, Solana, Bitcoin, and other alt-VMs
  • Aggregates across 18+ bridges and 20+ DEXs/aggregators per detailed sources

Cons

  • None significant found in our research

Real, LI.FI itself is primarily developer-facing infrastructure rather than a single consumer interface; actual end-user experience depends on which specific wallet or app embeds it. Real, disclosed Jumper Exchange as LI.FI's own consumer-facing front-end.

Why this scores at the midpoint: a genuinely capable infrastructure layer, though the actual end-user experience varies by which specific application you use, similar to Injective's infrastructure-first model earlier in this project.

Pros

  • Jumper Exchange provides a direct, official consumer-facing option

Cons

  • No single, consistent interface; experience varies by which app you use

Real, disclosed default protocol fee around 0.25%, though genuinely "integrator-tunable," meaning the actual fee a user pays depends on which specific app or wallet embeds LI.FI.

Why this scores at the midpoint: a disclosed, reasonable default fee, tempered by real, honest variability depending on which specific integration you use.

Pros

  • Disclosed, reasonable default protocol fee (~0.25%)

Cons

  • Actual fee genuinely varies by which specific integrator/app you use

Real, genuinely extensive product suite: same-chain swaps, cross-chain swaps, contract calls, multi-step flows, status tracking, intent-based execution, and newer workflow tools like Composer and Deposit.

Pros

  • Extensive, infrastructure-grade feature set (Composer, Deposit, multi-step flows)

Cons

  • These tools are built for developers integrating LI.FI, not end users directly
Where to get it

Access LI.FI through a specific, trusted wallet or app that embeds it, such as Jumper Exchange, its own official front-end.

Given the repeated 2022/2024 vulnerability pattern in newly-deployed facets, use finite approvals (the default) rather than infinite ones, and revoke old approvals periodically regardless of which specific app you use to access LI.FI's routing.

0/ 100

Genuinely essential infrastructure, carrying a pattern we can't fully explain away as one bad day.

LI.FI's real, substantive value is hard to overstate: it's the routing layer quietly making cross-chain UX work inside a huge number of wallets and apps most people use without ever knowing LI.FI's name. Its incident response in 2024 was genuinely exemplary: immediate action, a full public postmortem, and a precise, well-corroborated distinction that only a specific, non-default configuration was actually exposed. What keeps us from scoring this higher is something more specific than the dollar amount: at least one credible, technical source described the 2024 exploit as nearly identical to an earlier one in 2022. A single incident is a mistake. A repeated pattern in the same underlying architecture is a real, honest signal about whether the lesson from the first incident was fully absorbed the first time. We think that distinction deserves to show up in the score, not just in a footnote.

Best forDevelopers and wallets that need genuinely broad, multi-chain routing infrastructure to embed directly into their own products
Not forEnd users looking for a single, unified consumer app, or anyone who wants a platform with no repeated vulnerability history
Score Ledger
lifi · 7 line items
01Security15.0
02Routing15.0
03Decentralization6.5
04Coverage12.75
05UX6.0
06Fees6.0
07Extras3.75
TOTAL65.0
≈ 65 / 100; Essential infra, a pattern to watch

The scorecard above is deliberately general. Whether LI.FI is right for you depends heavily on which of these you already are.

Best fit

The developer or wallet builder who needs genuinely broad, multi-chain routing infrastructure to embed directly

This is exactly what LI.FI is built for, and where its real, distinctive value concentrates most heavily.

Good fit

The end user accessing LI.FI's routing through Jumper Exchange, its own official consumer front-end

This gives you a direct, official interface rather than relying on a third-party integration's specific choices.

Workable fit

The user who specifically uses finite approvals and revokes old permissions regularly

Given the repeated 2022/2024 vulnerability pattern, these specific habits genuinely matter more here than elsewhere.

Poor fit

Anyone who wants a platform with no repeated vulnerability history in its underlying architecture

Rango or CoW Swap, both reviewed earlier in this series, offer cleaner incident records for this specific priority.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; a repeated vulnerability pattern timelined across 2022 and 2024, the infinite-vs-finite approval distinction explained precisely, LI.FI's infrastructure role vs. Jumper Exchange, and our first nine-way aggregator comparison.

A repeated pattern, 2022 to 2024

2022 incidentJuly 2024 incident
Described asA prior exploit, per at least one detailed technical source"Nearly identical" to the 2022 incident, per the same source
Root causeNot detailed in our sourcesAn arbitrary-call vulnerability in a newly-deployed contract facet (GasZipFacet)
AmountNot specified in our sources~$11.6 million across 153 wallets
ResponseNot detailed in our sourcesFacet disabled immediately; full public postmortem published; additional deployment safeguards implemented

We found less detail available on the 2022 incident specifically than the well-documented 2024 one; we're presenting this comparison with that gap disclosed rather than filling it in with assumptions.

Infinite vs. finite approvals, precisely

Finite approval (default)Infinite approval
What it grantsPermission for one specific transactionOngoing, unlimited permission until manually revoked
Affected by July 2024 incident?No, confirmed unaffectedYes, this configuration was exploited
Default settingYes, in LI.FI's API, SDK, and widgetRequires actively opting in or using an older integration

This same finite-vs-infinite pattern determined who was affected in Matcha's January 2026 incident too, reviewed earlier in this series; it's becoming a consistent, real theme across this entire aggregator category.

LI.FI vs. Jumper Exchange

LI.FIJumper Exchange
What it isThe underlying routing and orchestration infrastructureLI.FI's own official consumer-facing front-end
Who uses it directlyWallets, DeFi apps, and developers via API/SDK/widgetEnd users wanting a direct interface

If you want a single, official, direct interface rather than accessing LI.FI through a third-party wallet's specific integration, Jumper Exchange is the more relevant starting point.

Nine aggregators, side by side

1inchJupiterRubicKyberSwapRangoVeloraCoW SwapMatchaLI.FI
Confirmed incidentsOneOneTwoOneNone foundNone foundTwoOne (naming caveat)Two (repeated pattern)
Chain scope13+Solana-onlyDisputed, wide17-2550-74+ (disputed)Cross-chain focus2 (EVM-only)16 (EVM-only)60+ (broadest)
Primary userEnd userEnd userEnd user + devs (SDK)End userEnd user + devs (SDK)End userEnd userEnd userDevs/wallets (infra-first)

LI.FI's chain coverage is the broadest we've documented in this series, consistent with its role as infrastructure meant to be embedded everywhere rather than a single destination app.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've excluded LI.FI's own official incident report and all third-party incident-specific technical analyses, since those are postmortems rather than general reviews.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands moderately below the aggregated industry average; most general reviews treat the 2024 incident as a single, well-handled event without weighing the repeated 2022/2024 vulnerability pattern as heavily as our methodology does.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, on July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets. At least one detailed technical source described this as nearly identical to an earlier exploit in 2022.

Only if you had granted infinite (unlimited, ongoing) token approval to LI.FI's contract. Wallets using finite approvals, LI.FI's own default setting in its API, SDK, and widget, were not affected.

Not primarily. LI.FI is infrastructure embedded inside many wallets and DeFi apps via API, SDK, and widget. If you want a direct, official interface, Jumper Exchange is LI.FI's own consumer-facing front-end.

60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, among the broadest coverage claims we found in this entire aggregator series.

No, not as of early 2026. Be cautious of any token claiming LI.FI affiliation on third-party exchanges; LI.FI itself has disclosed a direct warning about this.

A default protocol fee around 0.25%, though this is "integrator-tunable," meaning the actual fee you pay depends on which specific wallet or app you use to access LI.FI's routing.

A smart-contract standard (EIP-2535) where core logic sits in one contract that delegates to separate "facet" contracts for specific functions. The July 2024 exploit targeted a newly-deployed facet specifically, underscoring why rigorous review of new facets matters under this architecture.

LI.FI is embedded across a large number of wallets and DeFi apps as routing infrastructure; the specific list changes over time, and its own documentation is the best source for current integrations.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with LI.FI.

More Reviews