LI.FI · Vulnerability Disclosure

Lifi Vulnerability Disclosure

Vulnerability disclosure

LI.FI publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyCrypto Web3BlockchainCross-ChainBridgesDEX AggregationDeFiPaymentsLiquidityYieldIntentsAgents
Program:

Disclosure Policy

Policy

Security Contact

Contact
https://help.li.fi/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: false
probe_note: >-
  0-working/probe-security-programs.py returned vdp=none because LI.FI serves no
  /.well-known/security.txt and its disclosure content lives on the docs host
  rather than a /security path on the apex domain. The program below was found
  by reading the published security page directly.
source: https://docs.li.fi/introduction/learn-more/security-and-audits
policy:
- https://docs.li.fi/introduction/learn-more/security-and-audits
contact:
- https://help.li.fi/
security_txt: false
bug_bounty:
  platform: Cantina
  url: https://cantina.xyz/bounties/260585d8-a3e8-4d70-8077-b6f3f5f0391b
  max_reward_usd: 1000000
  scope: Smart contract vulnerabilities and other critical security issues.
audits:
  public: true
  url: https://github.com/lifinance/contracts/tree/main/audit/reports
  policy: >-
    No smart contract code reaches production without independent security
    review; multiple audit firms are engaged and all reports are published.
practices:
- Dedicated in-house blockchain/DeFi security team
- Annual third-party penetration testing of Web2 infrastructure (APIs, web apps, backends)
- Independent smart contract audits before every production deployment
- Automated Web3 security testing via Olympix
- Real-time smart contract monitoring, including third-party monitoring via Hexagate
- Anomaly detection with baseline behavioral models and emergency pause mechanisms
- Established incident response and post-incident analysis protocols
standards_alignment:
- OWASP guidelines for web application security
- Smart contract security best practices
- Secure development lifecycle methodologies
evidence:
- source: https://docs.li.fi/introduction/learn-more/security-and-audits
  kind: security-policy-page
  keywords: [bug bounty, responsible disclosure, audits, incident response]
- source: https://cantina.xyz/bounties/260585d8-a3e8-4d70-8077-b6f3f5f0391b
  kind: bug-bounty-program
page_last_updated: 'October 2025'