Share

Crypto Neobank Infini Loses $49.5M to Private Key Attack

Infini Earn Funds has fallen victim to not one but two devastating hacks, resulting in the theft of millions of dollars worth of USDC. 
Ephraim Emmanuel
Last updated:
24 February 2025 @ 12:01 UTC
Why Trust CTW

CTW is a fresh voice in the world of cryptocurrency, offering clear and insightful coverage of the ever-evolving digital asset landscape. Backed by a team of passionate writers and crypto enthusiasts, we dive deep into market trends, emerging technologies, and innovative blockchain projects. We hope to become your go-to source for up-to-date information in this fast-paced industry.

Infini

Share

Infini, a next-generation neobank specializing in stablecoins, has become the victim of a huge double hack, resulting in the loss of $49.5 million worth of USDC. The breach, which was traced back to a compromised private key, has raised urgent concerns about security vulnerabilities in the digital finance realm.

How the Hacks Unfolded

The hack at Infini seems like a well-calculated move. The hackers found a security flaw that allowed them to break into Infini’s system and steal 49.5 million USDC. After gaining access, the hackers quickly converted the stolen USDC into DAI, possibly to cover their tracks and make it harder for authorities to trace the stolen money. 

Next, the hackers used the DAI to purchase 17,696 ETH, likely on a decentralized exchange or a popular crypto platform, making their actions blend in with normal trades. Finally, they transferred the 17,696 ETH to a new wallet address, “0xfcc8…6e49.” This new address helped hide the stolen funds. However, moving such a large amount into one wallet could only attract attention and leave clues for investigators.

The Aftermath and Implications

The overall impact of these two hacks is a big loss that has left industry experts and everyday users alike grappling with the implications of such a devastating blow to confidence in DeFi protocols. Following the breach, the Infini’s co-founder issued a statement assuring customers that they would be compensated for any losses incurred. “Please rest assured that we will definitely compensate you and we can afford it,” she stated.

Meanwhile, just days before, popular digital asset exchange Bybit had its wallet compromised resulting in a high-class UI Spoofing attack, which led to a fraudulent transfer of $1.4 billion. The hack has since raised alarm about the inherent vulnerabilities even the most established and reputable digital currency exchanges face. 

Yet, in a remarkable turn of events, Bybit successfully recovered more than $43 million of the stolen assets. The recovery was made possible with the help of Polygon’s security team, which played a key role in retrieving the stolen funds. Additionally, Tether acted swiftly to freeze $181,000 in USDT linked to the hack, effectively cutting off further losses and demonstrating the proactive measures needed in the face of such rampant insecurity.

Ephraim Emmanuel

Enter your email for our Free Daily Newsletter.

Newsletter Subscribers (Home Footer}