← Radar

Incident case file

Sign in to watch

Lixir Finance — Broken EIP-2612 Permit Verification — Vault Token Drain

Incident date June 25, 2026

0 views

ActiveEthereumSmart contract vulnerability / forged permit signatureCluster: LIXIR-EIP2612-2026-06

Estimated loss

$12.3K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: 0x3fa8cf7fea68c8e76a9838d77889464ddfb6a6cf

Funds moved to: Net ~$12,300 extracted across many victim vault-token holders, consolidated into the attacker's wallet 0x3fa8cf7fea68c8e76a9838d77889464ddfb6a6cf via the exploit/helper contract 0xefd1b12f5e3c35d7dae0d1449674c247566f9b76. Assets drained: WETH, USDC, USDT, and LIX (Lixir Token) — note that LIX is effectively illiquid/near-worthless, so the realizable value for the attacker is likely lower than the nominal $12,300 figure. No further downstream movement (e.g., to a mixer or bridge) has been repor
Lixir Finance vault tokens (lv_* wrappers over Uniswap V3 LP positions) implemented a broken EIP-2612 permit: the contract only checked require(recovered != 0, "INVALID_SIGNATURE") and never verified that the ecrecover'd signer actually matched the token owner. The attacker reused a single dummy signature to grant their exploit contract (0xEFd1b12F...) approval over dozens of holders' vault tokens, then called withdrawFrom / withdrawETHFrom to burn each holder's shares and pull out the underlyin

Timeline: T0 (2026-06-25, exact time not disclosed in available sources): Attacker exploits the broken EIP-2612 permit implementation in Lixir Finance's vault tokens (lv_* wrappers over Uniswap V3 LP positions), reusing a single dummy/forged signature to obtain approval over dozens of holders' vault tokens via exploit contract 0xefd1b12f5e3c35d7dae0d1449674c247566f9b76. The attacker then calls withdrawFrom / withdrawETHFrom repeatedly to burn victim shares and extract the underlying WETH, USDC, USDT, and LIX tokens, consolidating proceeds at 0x3fa8cf7fea68c8e76a9838d77889464ddfb6a6cf. Exploit transaction: 0x17026faca0b8e4cb7531e4fb277c390eb165e81229628e0192923ad1d90a41da. T+1 day (2026-06-26, 07:24 UTC): DefimonAlerts (automated by @DecurityHQ) publishes the first public detection, confirming the ~$12.3K loss figure, the broken-permit root cause, the attacker address, the exploit transaction, and the (unverified) victim vault contract. Status as of report compilation: no official statement from Lixir Finance identified, no patch or recovery confirmed, no compensation announcement found.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)