CryptoReal
CASE FILE — Feb 24, 2025

Dormant Admin Key Lets Developer Empty Infini's Vault of $49.5 Million

Neobank Infini lost $49.5 million after its founder, known as Christian, discovered that a contractor he had once trusted with contract-level authority had never actually given it back. The developer sat on that access for 114 days before using it to empty the platform's vault.

The chain of events began with a single ETH sent from Tornado Cash, which funded the wallet that would go on to carry out the theft. From there, the attacker withdrew the funds as USDC, converted them to DAI, and finally rotated the proceeds into ETH — the whole cash-out sequence taking only minutes once triggered.

Investigators piecing together the on-chain trail concluded that the person responsible was not an outside hacker exploiting a code flaw, but a developer who had retained privileged administrative rights well after their contracted work was finished — and who waited for the vault's balance to grow before acting.

01How the theft came to light

The incident began late on a Sunday night, with a transaction that initially drew little attention. Blockchain trackers picked up on it quickly nonetheless.

LookOnChain flagged the activity first, reporting that a freshly created wallet had spent 49.5 million DAI to purchase 17,696 ETH at a price of $2,798 within the span of an hour.

Minutes later, YAM corroborated the report, stating that roughly $50 million in Infini Earn deposits had been stolen and routed to an address funded via Tornado Cash, with the source of funds traced back to the Morpho MEVCapital Usual USDC Vault.

BlockSec added its own assessment, describing the incident simply as an attack against an unverified contract on Ethereum.

Infini's founder Christian acknowledged the breach shortly after, framing it with a mix of resignation and reassurance: he noted that a friend had once joked he'd had an unusually smooth run, and that while he'd always expected some setback eventually, he hadn't anticipated becoming a victim so soon after the Bybit incident. He clarified that his own private key remained secure, but admitted he had been careless in an earlier transfer of authority, calling the outcome ultimately his own responsibility.

Infini's official account, by contrast, stayed quiet for close to eight hours before issuing a statement apologizing for the concern caused and saying the team was investigating around the clock. By that point, the $49.5 million was already gone. There was no flash loan involved and no price manipulation — just standing administrative access, used to walk away cleanly.

02Tracing the backdoor

Sums referenced in this case file

Two addresses sit at the center of the exploit: the contract used by the attacker, and the account that deployed it. Rather than a spontaneous exploit, the setup appears to have been built into the system from the start.

Forensic work by QuillAudits, reported by Decrypt, traced the root cause to a compromised private key tied to the deploying account, which had been assigned a special role — identified as 0x8e0b — granting the ability to pull all assets out of the vault. Using that standing permission, the attacker executed two rapid withdrawals from MEV Capital's Usual USDC vault.

03Sequence of the attack

After waiting 114 days, the attacker moved with a clear, prepared plan:

  1. The attack wallet was seeded with 1 ETH sourced from Tornado Cash.
  2. A malicious contract was deployed, made to resemble a legitimate piece of Infini's vault infrastructure.
  3. Admin privileges — referenced elsewhere as role 0x8e9b — were used to authorize asset withdrawals.
  4. $49.5 million in USDC was pulled out across two separate transactions:
    • Transaction one: 11.5 million USDC withdrawn and sent to a wallet funded through Tornado Cash.
    • Transaction two: 38 million USDC withdrawn and swapped into DAI through Maker's Sky Protocol.
  5. The USDC-to-DAI conversion served to sidestep any potential blacklisting of the funds.
  6. The DAI was then swapped into approximately 17,700 ETH.
  7. The proceeds were moved to a newly created address.

QuillAudits pointed out that the attacker didn't layer on additional obfuscation beyond this point, meaning the funds could theoretically still be traced — though that offers little practical relief with the assets sitting untouched in the attacker's wallet. The overall approach favored speed: pull out as much as possible immediately, move it into assets that couldn't easily be frozen, and rely on Tornado Cash to obscure the trail.

04Christian's shifting response

In the hours following the theft, Infini's founder cycled through several public positions. He first maintained that ordinary deposits and withdrawals on the platform were unaffected. He then stated that roughly 70% of the stolen $50 million belonged to major investors he knew personally, that he had reached out to each of them individually, and that he intended to cover the losses himself and settle the matter privately.

Less than twelve hours after the theft, his tone shifted toward negotiation: addressing the attacker directly on the assumption they might be watching, he offered to let them keep 20% of the stolen funds and promised no legal pursuit if the rest were returned. Whether or not the offer landed, the funds had already left the building.

05A familiar failure mode

The Infini case arrived just days after Bybit's $1.43 billion loss, reinforcing a pattern that has little to do with clever exploit code. This wasn't a zero-day bug or an intricate reentrancy attack — by all accounts, it came down to a developer who was simply never stripped of access they no longer needed.

As the QuillAudits research team told Decrypt, the frustrating part is that this isn't a novel category of problem — similar failures keep recurring, yet organizations continue to underestimate how much discipline access control actually requires.

Strip away the technical framing and the root cause is mundane: no process required that privileges be handed back after a project ended, no expiration was placed on elevated access, and no multi-signature requirement protected the vault's most sensitive functions. Infini effectively ran on faith in an unnamed developer who quietly held onto a backdoor and waited for the right moment.

The broader point QuillAudits made is that crypto's pitch of removing third-party trust doesn't hold up if a project still hands unchecked power to a single anonymous contributor. A platform meant to protect user funds ended up unable to protect its own keys. As the team put it, the fix isn't purely technical — it's a matter of habits and process, not just smart contract features. Until organizations start treating access management as a top-tier security priority rather than an afterthought, incidents like this one are likely to keep happening.

Admin PrivilegesInfini
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.