Stablecoin DeFi bank Infini suffers $49M exploit after attacker retains admin-level control

Fonte Cryptopolitan

A hacker drained over $49M in USDC from the Infini stablecoin bank. The exploit may be due to insider access to a smart contract, where the developer retained access after delivering to Infini. 

Admin access to a smart contract allowed an exploiter to drain $49M from the Infini protocol, a stablecoin DeFi bank. Infini itself has not reacted to the exploit, or explained the nature of the hack. Infini is a crypto card issuer, taking stablecoin collateral to perform daily payments. 

Infini advertised its payment services as a neobank, mixing crypto and traditional finance. The product drew in 500% more users in the past few weeks, as it started its card campaigns. The neobank also offers high-yield earnings products, leading to a rise in available liquidity for the exploiter.

It was precisely the yield products that created the conditions for the exploit, as funds were reportedly taken from the Morpho MEV Capital Usual USDC Vault. Morpho has not issued any warnings or reported lost funds.

The exploit was noted after a regular-looking whale transaction, where a new wallet withdrew all funds locked in the contract. The attacker’s wallet was known to Infini, as the project reportedly ordered the exploiter to create the smart contract. Unknown to the project, the attacker retained admin rights and could make the call to drain all liquidity. 

The immediate action of the exploiter was to swap out of USDC to buy 17,696 ETH. The exploiter went through DAI, which was available through decentralized protocols. The funds moved through Uniswap, Sky Protocol, and 0x Protocol. Swapping out of USDC as fast as possible allowed the hacker to move funds into ETH, which cannot be frozen, only blacklisted from exchanges.

After that, the attacker split the proceeds into smaller sums and multiple addresses. The exploiter used a new wallet to send a small amount of ETH for gas and complete the transaction. The initial funding for the wallet came from Tornado Cash, veiling a part of the on-chain presence of the hacker.

After that, the ETH was moved through a series of transfers. At the time of writing, the funds were still not mixed. 

Did DPRK hackers strike again?

The identity of the contract creator remains unknown, as Infini has not revealed who was ordered to build the smart contract. 

The Infini hack follows the biggest exploit of 2025, where the Bybit exchange lost up to $1.5B in Ethereum (ETH). The Bybit hacker had a similar approach of splitting ETH before mixing. On-chain investigator ZachXBT has pointed out multiple examples that this approach is one of the signature moves of the Lazarus hacker group. For now, Infini has not linked any of the exploiter’s wallets to other known Lazarus addresses. 

This time, no private keys were leaked, and Infini has not stopped withdrawals and deposits. 

The founder of Infini, @christianeth, took full responsibility for the exploit, stating he was negligent in the authority transfer process from the developer to the project. The founder reassured users that the protocol remains liquid, and will issue full compensation in the worst-case scenario. 

My personal private key has not been leaked, so there is no need to worry too much. I was negligent when transferring the authority before. It is ultimately my responsibility. This has sounded the alarm…There is no problem with liquidity. Full compensation can be paid and the funds are being traced,” wrote @christianeth on X.

Other on-chain analysis shows a potential private key leak, which allowed the hacker access to the contract. PeckShield noted the engineer turned hacker has been identified. After the attack, one of the Infini co-founders, @0xsexybanana, deleted her X account. The current heist is a suspected insider attack, as the engineer was trusted enough to create a smart contract. 

The recent exploits and hoarding of ETH raised the question of using the chain for money laundering and potentially hostile regime financing. At the same time, the exploits catalyzed a small ETH rally, where the asset rose above $2,800 for the first time in weeks. The ETH losses meant exchanges had to recoup their reserves, leading to additional demand.

Cryptopolitan Academy: How to Write a Web3 Resume That Lands Interviews - FREE Cheat Sheet

Isenção de responsabilidade: Apenas para fins informativos. O desempenho passado não é indicativo de resultados futuros.
placeholder
Previsão do preço do ouro: XAU/USD mantém ganhos em meio à aversão ao risco e à queda dos rendimentosO preço do ouro se agarra a ganhos decentes acima de 0,15% durante a sessão norte-americana de terça-feira, em meio à aversão ao risco, juntamente com a força geral do dólar americano (USD).
Autor  FXStreet
10 jan. 2024
O preço do ouro se agarra a ganhos decentes acima de 0,15% durante a sessão norte-americana de terça-feira, em meio à aversão ao risco, juntamente com a força geral do dólar americano (USD).
placeholder
Os aliados republicanos de Trump são perturbados pelo Doge de Elon MuskA equipe de Elon vem acabando com agências em todo o governo federal desde a inauguração de Trump, com os trabalhadores da Doge demitindo milhares de funcionários.
Autor  Cryptopolitan
10 horas atrás
A equipe de Elon vem acabando com agências em todo o governo federal desde a inauguração de Trump, com os trabalhadores da Doge demitindo milhares de funcionários.
placeholder
O CEO da Polygon Labs vê Bitcoin atingindo US $ 250 mil, citando sua simplicidade e escassezMarc Boiron, CEO da Polygon Labs, espera que o BTC atinja US $ 250.000, acreditando que o crescimento a longo prazo do token é inevitável, apesar da volatilidade do mercado de curto prazo.
Autor  Cryptopolitan
10 horas atrás
Marc Boiron, CEO da Polygon Labs, espera que o BTC atinja US $ 250.000, acreditando que o crescimento a longo prazo do token é inevitável, apesar da volatilidade do mercado de curto prazo.
placeholder
Playbook de President Trump para proteger o poder global do dólar americanoO controle do dólar dos EUA sobre as finanças globais está sob ataque, e Trump está garantindo que ele permaneça no controle. China, Hong Kong, Tailândia, Emirados Árabes Unidos e Arábia Saudita estão construindo silenciosamente uma moeda digital do banco central transfronteiriço (CBDC) chamado Mbridge, projetado para deixá-los negociar sem a necessidade de dólares ou Swift. O banco para […]
Autor  Cryptopolitan
10 horas atrás
O controle do dólar dos EUA sobre as finanças globais está sob ataque, e Trump está garantindo que ele permaneça no controle. China, Hong Kong, Tailândia, Emirados Árabes Unidos e Arábia Saudita estão construindo silenciosamente uma moeda digital do banco central transfronteiriço (CBDC) chamado Mbridge, projetado para deixá-los negociar sem a necessidade de dólares ou Swift. O banco para […]
placeholder
Previsão do preço do ouro: XAU/USD atrai alguns vendedores abaixo de US$ 2.950 com a realização de lucrosO preço do ouro (XAU/USD) caiu para perto de US$ 2.925 durante o pregão asiático de segunda-feira.
Autor  FXStreet
9 horas atrás
O preço do ouro (XAU/USD) caiu para perto de US$ 2.925 durante o pregão asiático de segunda-feira.
goTop
quote