Infini Hack

Reported loss $50.0M
Ethereum
Dev Privilege Oversight Exploit

What happened

On February 24, 2025, Infini lost about $50 million in USDC after an address with administrative privileges granted itself a redemption role and withdrew funds from an Infini-linked contract. Public analyses described the actor as a former developer, but that attribution remains an allegation rather than a proven identity.

Technical root cause

The privileged address could grant a redemption role and register a withdrawal destination. Control of that address therefore enabled access to funds held by the protocol. The reviewed analysis does not establish how its signing authority was obtained.

How it happened

  1. The attacker controlled an address that retained or obtained administrative authority.
  2. That authority was used to grant the address REDEEMER_ROLE.
  3. The new role permitted redemption of approximately 49.5 million USDC from the contract.
  4. Analysts linked the address to a former developer, while the precise key-compromise route remains unknown.

Protocol details

Classification Protocol Logic / Stablecoin / Key Compromise
Protocol Type Exploit/Access control
Protocol links Website @0xinfini

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.