LI.FI:
the infrastructure behind countless wallets, carrying a real, repeated vulnerability pattern.
We tore apart LI.FI, a cross-chain liquidity aggregation and routing layer embedded inside a large number of wallets and DeFi apps, across the same aggregator-adapted scorecard we've used throughout this series. From genuinely broad reach across 60+ blockchain networks spanning EVM chains, Solana, Bitcoin, and other alt-VMs, a comprehensive product suite combining bridges, DEXs, and intent-based solvers behind one integration, and a genuinely transparent, detailed public incident report, to a real, genuinely concerning finding worth centering directly: on July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets, and at least one detailed, credible security firm described this as nearly identical to a prior exploit in 2022, a real, repeated vulnerability pattern within the same underlying architecture. We found a well-corroborated, important distinction: the exploit was confirmed limited to wallets using infinite token approvals, with finite approvals, LI.FI's own default setting, unaffected; and landed on a score the marketing page won't show you.
Our take, up front: LI.FI is genuinely different from most platforms we've reviewed in this aggregator series: rather than a single consumer app, it's a routing and orchestration layer, embedded via API, SDK, and widget inside a large number of wallets and DeFi apps, connecting users to bridges, DEXs, and intent-based solvers across a single integration. Real, genuinely broad reach across 60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, among the broadest chain coverage claims we've found in this entire series. Real, genuinely extensive product suite built for embedding: same-chain swaps, cross-chain swaps, contract calls, multi-step flows, status tracking, intent-based execution, and newer workflow tools like Composer and Deposit. Real, disclosed audits from named firms including Code4rena and Quantstamp. Real, honest, notable absence of a publicly traded token as of early 2026, alongside a real, disclosed, proactive warning that any token claiming LI.FI affiliation on third-party exchanges should be treated with suspicion. What we can't set aside: a real, genuinely concerning finding. On July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets on Ethereum and Arbitrum; critically, at least one detailed, credible security firm described this as nearly identical to a prior exploit in 2022, a real, repeated vulnerability pattern within the same underlying Diamond Pattern architecture. Real, genuinely important, well-corroborated distinction: the exploit was confirmed limited specifically to wallets using infinite token approvals; finite approvals, the default setting in LI.FI's own API, SDK, and widget, were not affected. Real, genuinely positive, disclosed incident response: the vulnerable facet was disabled across all chains immediately, and a full, detailed, technical incident report was published directly. Real, disclosed default protocol fee around 0.25%, though genuinely "integrator-tunable," meaning the actual fee a user pays depends on which specific app or wallet embeds LI.FI. We weighted all of it below.
Real, genuinely important, well-corroborated two-incident history: a July 2024 exploit ($11.6 million, per LI.FI's own detailed incident report, affecting 153 wallets on Ethereum and Arbitrum) via an arbitrary-call vulnerability in a newly-deployed contract facet, and at least one detailed, credible technical source describing this as nearly identical to a prior 2022 exploit, a genuinely concerning, real repeated vulnerability pattern. Real, genuinely important, well-corroborated distinction: the exploit was confirmed limited specifically to wallets using infinite token approvals; finite approvals, the default setting in LI.FI's own API, SDK, and widget, were not affected. Real, genuinely positive, disclosed incident response: the vulnerable facet was disabled across all chains immediately, and a full, detailed, technical incident report was published. Real, disclosed audits from named firms including Code4rena and Quantstamp.
Pros
- Full, detailed, technical incident report published directly; vulnerable facet disabled immediately
- Finite approvals (the default) confirmed unaffected in the 2024 incident
- Disclosed audits from named firms (Code4rena, Quantstamp)
Cons
- Jul 2024: $11.6M exploit via a newly-deployed facet, affecting 153 wallets
- At least one credible source describes this as nearly identical to a 2022 exploit
Real, genuinely broad, well-documented aggregation combining bridges, DEXs, and intent-based solvers behind a single integration, tapping liquidity from major sources including Uniswap, 1inch, Stargate, and Across. Real, genuinely distinctive infrastructure positioning: rather than a single consumer app, LI.FI is the routing layer embedded inside a large number of wallets and DeFi apps.
Pros
- Comprehensive aggregation combining bridges, DEXs, and intent-based solvers
- Embedded infrastructure role across many wallets and apps
Cons
- Actual routing quality experienced depends partly on which integrator's configuration you use
Real, genuinely non-custodial. Real, honest, notable absence of a publicly traded token as of early 2026, alongside a real, important disclosed warning that any token claiming LI.FI affiliation on third-party exchanges should be treated with suspicion.
Pros
- Genuinely non-custodial; proactive, disclosed warning against fake affiliated tokens
Cons
- No publicly traded token means no direct, disclosed governance mechanism for users to weigh
Real, genuinely broad reach across 60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, a genuinely wide scope even relative to other broad aggregators in this series.
Pros
- 60+ chains including EVM, Solana, Bitcoin, and other alt-VMs
- Aggregates across 18+ bridges and 20+ DEXs/aggregators per detailed sources
Cons
- None significant found in our research
Real, LI.FI itself is primarily developer-facing infrastructure rather than a single consumer interface; actual end-user experience depends on which specific wallet or app embeds it. Real, disclosed Jumper Exchange as LI.FI's own consumer-facing front-end.
Pros
- Jumper Exchange provides a direct, official consumer-facing option
Cons
- No single, consistent interface; experience varies by which app you use
Real, disclosed default protocol fee around 0.25%, though genuinely "integrator-tunable," meaning the actual fee a user pays depends on which specific app or wallet embeds LI.FI.
Pros
- Disclosed, reasonable default protocol fee (~0.25%)
Cons
- Actual fee genuinely varies by which specific integrator/app you use
Real, genuinely extensive product suite: same-chain swaps, cross-chain swaps, contract calls, multi-step flows, status tracking, intent-based execution, and newer workflow tools like Composer and Deposit.
Pros
- Extensive, infrastructure-grade feature set (Composer, Deposit, multi-step flows)
Cons
- These tools are built for developers integrating LI.FI, not end users directly
Access LI.FI through a specific, trusted wallet or app that embeds it, such as Jumper Exchange, its own official front-end.
Given the repeated 2022/2024 vulnerability pattern in newly-deployed facets, use finite approvals (the default) rather than infinite ones, and revoke old approvals periodically regardless of which specific app you use to access LI.FI's routing.
Genuinely essential infrastructure, carrying a pattern we can't fully explain away as one bad day.
LI.FI's real, substantive value is hard to overstate: it's the routing layer quietly making cross-chain UX work inside a huge number of wallets and apps most people use without ever knowing LI.FI's name. Its incident response in 2024 was genuinely exemplary: immediate action, a full public postmortem, and a precise, well-corroborated distinction that only a specific, non-default configuration was actually exposed. What keeps us from scoring this higher is something more specific than the dollar amount: at least one credible, technical source described the 2024 exploit as nearly identical to an earlier one in 2022. A single incident is a mistake. A repeated pattern in the same underlying architecture is a real, honest signal about whether the lesson from the first incident was fully absorbed the first time. We think that distinction deserves to show up in the score, not just in a footnote.
The scorecard above is deliberately general. Whether LI.FI is right for you depends heavily on which of these you already are.
The developer or wallet builder who needs genuinely broad, multi-chain routing infrastructure to embed directly
This is exactly what LI.FI is built for, and where its real, distinctive value concentrates most heavily.
The end user accessing LI.FI's routing through Jumper Exchange, its own official consumer front-end
This gives you a direct, official interface rather than relying on a third-party integration's specific choices.
The user who specifically uses finite approvals and revokes old permissions regularly
Given the repeated 2022/2024 vulnerability pattern, these specific habits genuinely matter more here than elsewhere.
Anyone who wants a platform with no repeated vulnerability history in its underlying architecture
Rango or CoW Swap, both reviewed earlier in this series, offer cleaner incident records for this specific priority.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; a repeated vulnerability pattern timelined across 2022 and 2024, the infinite-vs-finite approval distinction explained precisely, LI.FI's infrastructure role vs. Jumper Exchange, and our first nine-way aggregator comparison.
A repeated pattern, 2022 to 2024
| 2022 incident | July 2024 incident | |
|---|---|---|
| Described as | A prior exploit, per at least one detailed technical source | "Nearly identical" to the 2022 incident, per the same source |
| Root cause | Not detailed in our sources | An arbitrary-call vulnerability in a newly-deployed contract facet (GasZipFacet) |
| Amount | Not specified in our sources | ~$11.6 million across 153 wallets |
| Response | Not detailed in our sources | Facet disabled immediately; full public postmortem published; additional deployment safeguards implemented |
We found less detail available on the 2022 incident specifically than the well-documented 2024 one; we're presenting this comparison with that gap disclosed rather than filling it in with assumptions.
Infinite vs. finite approvals, precisely
| Finite approval (default) | Infinite approval | |
|---|---|---|
| What it grants | Permission for one specific transaction | Ongoing, unlimited permission until manually revoked |
| Affected by July 2024 incident? | No, confirmed unaffected | Yes, this configuration was exploited |
| Default setting | Yes, in LI.FI's API, SDK, and widget | Requires actively opting in or using an older integration |
This same finite-vs-infinite pattern determined who was affected in Matcha's January 2026 incident too, reviewed earlier in this series; it's becoming a consistent, real theme across this entire aggregator category.
LI.FI vs. Jumper Exchange
| LI.FI | Jumper Exchange | |
|---|---|---|
| What it is | The underlying routing and orchestration infrastructure | LI.FI's own official consumer-facing front-end |
| Who uses it directly | Wallets, DeFi apps, and developers via API/SDK/widget | End users wanting a direct interface |
If you want a single, official, direct interface rather than accessing LI.FI through a third-party wallet's specific integration, Jumper Exchange is the more relevant starting point.
Nine aggregators, side by side
| 1inch | Jupiter | Rubic | KyberSwap | Rango | Velora | CoW Swap | Matcha | LI.FI | |
|---|---|---|---|---|---|---|---|---|---|
| Confirmed incidents | One | One | Two | One | None found | None found | Two | One (naming caveat) | Two (repeated pattern) |
| Chain scope | 13+ | Solana-only | Disputed, wide | 17-25 | 50-74+ (disputed) | Cross-chain focus | 2 (EVM-only) | 16 (EVM-only) | 60+ (broadest) |
| Primary user | End user | End user | End user + devs (SDK) | End user | End user + devs (SDK) | End user | End user | End user | Devs/wallets (infra-first) |
LI.FI's chain coverage is the broadest we've documented in this series, consistent with its role as infrastructure meant to be embedded everywhere rather than a single destination app.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've excluded LI.FI's own official incident report and all third-party incident-specific technical analyses, since those are postmortems rather than general reviews.
Our score lands moderately below the aggregated industry average; most general reviews treat the 2024 incident as a single, well-handled event without weighing the repeated 2022/2024 vulnerability pattern as heavily as our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes, on July 16, 2024, an arbitrary-call vulnerability in a newly-deployed contract facet resulted in roughly $11.6 million in losses across 153 wallets. At least one detailed technical source described this as nearly identical to an earlier exploit in 2022.
Only if you had granted infinite (unlimited, ongoing) token approval to LI.FI's contract. Wallets using finite approvals, LI.FI's own default setting in its API, SDK, and widget, were not affected.
Not primarily. LI.FI is infrastructure embedded inside many wallets and DeFi apps via API, SDK, and widget. If you want a direct, official interface, Jumper Exchange is LI.FI's own consumer-facing front-end.
60+ blockchain networks, including EVM chains, Solana, Bitcoin, and other alt-VMs, among the broadest coverage claims we found in this entire aggregator series.
No, not as of early 2026. Be cautious of any token claiming LI.FI affiliation on third-party exchanges; LI.FI itself has disclosed a direct warning about this.
A default protocol fee around 0.25%, though this is "integrator-tunable," meaning the actual fee you pay depends on which specific wallet or app you use to access LI.FI's routing.
A smart-contract standard (EIP-2535) where core logic sits in one contract that delegates to separate "facet" contracts for specific functions. The July 2024 exploit targeted a newly-deployed facet specifically, underscoring why rigorous review of new facets matters under this architecture.
LI.FI is embedded across a large number of wallets and DeFi apps as routing infrastructure; the specific list changes over time, and its own documentation is the best source for current integrations.
More Reviews
1inch – DEX Aggregator Review
Score: 75/100. Category-defining aggregator; a Mar 2025 resolver incident (~$5M) didn't touch user funds, but did touch trust.
Read MoreJupiter – DEX Aggregator Review
Score: 78/100. Highest score in this whole project: ~95% Solana share, with the one 2024 phishing incident purely user-side.
Read MoreRubic – DEX Aggregator Review
Score: 51/100. Lowest in this sub-series: two 2022 hacks and unresolved, wide gaps in its own claimed audit scope.
Read MoreKyberSwap – DEX Aggregator Review
Score: 63.5/100. Dual aggregator+AMM; the Nov 2023 Elastic exploit left the aggregator itself confirmed unaffected.
Read More



