Infini Hack
What happened
On February 24, 2025, Infini lost about $50 million in USDC after an address with administrative privileges granted itself a redemption role and withdrew funds from an Infini-linked contract. Public analyses described the actor as a former developer, but that attribution remains an allegation rather than a proven identity.
The privileged address could grant a redemption role and register a withdrawal destination. Control of that address therefore enabled access to funds held by the protocol. The reviewed analysis does not establish how its signing authority was obtained.
How it happened
- The attacker controlled an address that retained or obtained administrative authority.
- That authority was used to grant the address REDEEMER_ROLE.
- The new role permitted redemption of approximately 49.5 million USDC from the contract.
- Analysts linked the address to a former developer, while the precise key-compromise route remains unknown.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.