Incident case file
Sign in to watchLixir Finance — Broken EIP-2612 Permit Verification — Vault Token Drain
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x3fa8cf7fea68c8e76a9838d77889464ddfb6a6cf
Timeline: T0 (2026-06-25, exact time not disclosed in available sources): Attacker exploits the broken EIP-2612 permit implementation in Lixir Finance's vault tokens (lv_* wrappers over Uniswap V3 LP positions), reusing a single dummy/forged signature to obtain approval over dozens of holders' vault tokens via exploit contract 0xefd1b12f5e3c35d7dae0d1449674c247566f9b76. The attacker then calls withdrawFrom / withdrawETHFrom repeatedly to burn victim shares and extract the underlying WETH, USDC, USDT, and LIX tokens, consolidating proceeds at 0x3fa8cf7fea68c8e76a9838d77889464ddfb6a6cf. Exploit transaction: 0x17026faca0b8e4cb7531e4fb277c390eb165e81229628e0192923ad1d90a41da. T+1 day (2026-06-26, 07:24 UTC): DefimonAlerts (automated by @DecurityHQ) publishes the first public detection, confirming the ~$12.3K loss figure, the broken-permit root cause, the attacker address, the exploit transaction, and the (unverified) victim vault contract. Status as of report compilation: no official statement from Lixir Finance identified, no patch or recovery confirmed, no compensation announcement found.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)