CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Crypto Neo-Bank Infini Hit By $50 Million Exploit
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Crypto Neo-Bank Infini Hit By $50 Million Exploit
News

Crypto Neo-Bank Infini Hit By $50 Million Exploit

CoinRSS
Last updated: February 25, 2025 12:34 am
CoinRSS Published February 25, 2025
Share

Crypto neo-bank Infini lost $49.5 million in a hack allegedly carried out by a former developer abusing administrative privileges.

The attacker, who had worked on Infini’s contract, leveraged their privileges after the project was completed to drain funds from the platform, according to blockchain analytics platform Cyvers.

In a report shared with Decrypt, smart contract audit firm QuillAudits confirmed that the exploit resulted from “compromised access and privilege escalation,” with the attacker exploiting a private key breach that granted them access to a compromised account.

“The hacker gained access to a private key associated with the account “0xc4…3e1,” the report notes. “This account had been granted a special role (0x8e0b) that allowed it to withdraw funds from the vault.”

🚨ALERT🚨Today, @0xinfini suffered a $49M $USDC exploit due to an attacker abusing retained administrative privileges.

The attacker, operating from 0xc49b5e5b9da66b9126c1a62e9761e6b2147de3e1, had initially developed the contract as part of the Infini project. However, after… pic.twitter.com/olguOyNCJr

— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) February 24, 2025

The hacker reportedly initiated two transactions—$11.45 million in the first and $38.06 million in the second—leading to the total stolen amount of $49.5 million from the Morpho MEVCapital USDC Vault.

The funds were then quickly swapped from USD Coin (USDC) into Dai (DAI) and converted into 17,696 ETH. Then the funds were transferred to a secondary address.

Following the breach, Christian Li, Infini’s founder, took to Twitter to acknowledge the incident and offer reassurance. He said the team had been “negligent when transferring the authority before.”

“It is ultimately my responsibility this has sounded the alarm,” Li said. “There is no problem with liquidity… full compensation can be paid and the funds are being traced.”

Despite the breach, Infini continued to allow withdrawals. Li reassured users that “full compensation can be paid” in the worst-case scenario.

Li expressed hope for recovering the stolen funds and offered the hacker 20% of the stolen amount, assuring that no legal action would be taken if the funds were returned.

I know hackers might be watching my tweets, so here’s my sincere message: I’ve done my best to show there are still good, responsible individuals in this industry. I deeply regret my mistakes and will work to make things right for my users.

I hope there’s a way to recover what…

— Christian (Building @0xinfini) (@Christianeth) February 24, 2025

The lack of further obfuscation techniques means the stolen assets might still be traceable, QuillAudits report notes.

Cyvers provided an analysis stating that the hacker, retaining the admin rights, went undetected for over 100 days, later funneling the stolen funds through the Ethereum-based coin mixer Tornado Cash.

“This incident highlights the critical risks of retained administrative privileges in smart contracts,” Hakan Unal, Senior Blockchain Scientist at Cyvers Ai, told Decrypt. “In the meantime, this serves as a strong reminder for projects to thoroughly audit and revoke unnecessary permissions post-deployment.”

Infini shared its official statement hours after the hack—saying all transactions, including transfers, deposits, and withdrawals, remained unaffected.

“We’re deeply sorry for the concern this causes – our team is working around the clock to investigate and secure all systems at the moment,” Infini tweeted on Monday.

We’re aware of reports on a security compromise affecting Infini. We’re deeply sorry for the concern this causes – our team is working around the clock to investigate and secure all systems at the moment.

All transfers, deposits, withdrawals, and payments remain in normal usage…

— Infini (@0xinfini) February 24, 2025

“It’s frustrating because these aren’t new problems,” QuillAudits research team told Decrypt. “We’ve seen this play out repeatedly, yet projects still underestimate how critical it is to lock down access.”

The team shared that until teams start treating access control as a “core security priority,” and not an afterthought, these hacks will keep happening.

“It’s not just about better tech; it’s about better habits,” the research team said.

The breach at Infini follows a major exploit at crypto exchange Bybit, which suffered a massive loss of $1.4 billion in Ethereum and related tokens last Friday, marking one of the biggest hacks in the industry’s history.

On-chain analysis revealed Lazarus Group, a North Korean state-sponsored hacking group, to be behind the attack.

Bybit’s response was similar to Infini’s in some ways, as the exchange opted to keep withdrawals open and vowed to cover the loss if the funds could not be recovered.

The hack comes amid growing concerns about security in the DeFi space, with over $2.2 billion in crypto stolen last year, and 50% of the stolen funds linked to North Korean hacking groups, as per blockchain analysis firm Chainlalysis’ report.

“The number of individual hacking incidents went up from 282 incidents in 2023 to 303 incidents in 2024,” the report said.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

Whale converts $5M USDC into 630K TRUMP tokens via new wallets – Bullish trend ahead?

Bitcoin mining power hits record highs – What it means for BTC’s price

Illinois Introduces Bitcoin Reserve Bill, Joining Growing List of States

YGG Launches New Publishing Arm, Debuts First Game ‘LOL Land’

Bitcoin’s declining investor interest – Is a long-term downturn on the way?

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Altcoin trading volume hits 3-year low— What this means for investors
Next Article Strategy Hints at New Bitcoin Buy
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Can Pi Network’s bulls enforce a reversal in the face of steady selling pressure?
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?