{"investigation":{"slug":"infini","entity_name":"Infini","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Infini is a Hong Kong-based stablecoin neobank offering yield-bearing accounts and a global payment card. On February 24, 2025, a former developer who had covertly retained administrative privileges over Infini's smart contracts drained approximately $49.5 million in USDC from the Morpho MEVCapital vault, converting the funds to ETH and routing them through Tornado Cash. As of May 2026, no funds have been recovered, and the attacker's wallet remained active through at least February 2026.","sections":[{"content":"Infini (stylized 0xInfini, operated at infini.money) is a stablecoin-native neobank headquartered in Hong Kong. The platform describes itself as a 'Pay-Fi' product that bridges stablecoin finance with real-world payments. Core offerings include yield-bearing stablecoin accounts (backed by on-chain positions in protocols such as Morpho and MEVCapital vaults), a global virtual payment card compatible with Apple Pay, Google Pay, Alipay, and PayPal, and treasury management tools targeting businesses. The platform reported over 50,000 active users prior to the February 2025 exploit. Christian Li is identified as the company's founder and CEO. Infini is described as an authorized trust and company service provider under Hong Kong regulations, though no independent confirmation of specific licensing details was found in available sources. The company continued operating and announced new product features — including reduced stablecoin transaction fees — as late as May 2025.","heading":"Background","sources":[{"url":"https://www.infini.money/","name":"","type":"other","credibility":3},{"url":"https://www.crypto-reporter.com/newsfeed/infini-launches-global-card-offering-daily-stablecoin-yield-96784/","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/neobank-infini-celebrates-50m-tvl-then-suffers-49-5m-exploit-due-to-former-insider/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 24, 2025, blockchain security firm CertiK detected unauthorized transfers from an Infini-linked Ethereum contract at approximately 3:18 am UTC. The root cause was identified as a failure of access-control management: an anonymous developer who had been hired to build and deploy Infini's smart contracts covertly retained a privileged administrative role (role identifier 0x8e0b) after project completion. This role granted the holder the ability to drain all assets held in the vault. The developer is alleged to have done so intentionally and to have waited approximately 114 days — the time required for the vault's total value locked (TVL) to reach a sufficiently large sum — before executing the attack. The attack was funded by 1 ETH drawn from Tornado Cash to cover gas fees, establishing deliberate premeditation. Two transactions were executed: the first drained 11,301,933 resolvUSDC (approximately $11.45 million in USDC); the second drained 35,654,943 USUALUSDC+ (approximately $35.65 million in USDC), for a combined total of roughly $49.5 million. The attacker called function 0x1c8c8fe2() to whitelist a receiving address (0x3ac96134fb0e42a52d33045aee50b89790f05ed0), then called function 0xcfda09ef() to redeem vault tokens without additional permission checks. Founder Christian Li publicly acknowledged the team's failure: 'I was negligent when transferring the authority before. It is ultimately my responsibility.' The compromised account address is 0xc49b5e5b9da66b9126c1a62e9761e6b2147de3e1. The vulnerable contract is 0x9a79f4105a4e1a050ba0b42f25351d394fa7e1dc.","heading":"The Insider Exploit","sources":[{"url":"https://www.certik.com/blog/0xinfini-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-infini-hack-february-2025","name":"","type":"other","credibility":3},{"url":"https://decrypt.co/307513/crypto-neo-bank-infini-50-million-exploit","name":"","type":"other","credibility":3},{"url":"https://invezz.com/news/2025/02/24/crypto-neobank-infini-exploited-for-50m-rogue-developer-suspected/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The on-chain trail of the attack is well-documented across multiple security research firms. The attack originated from compromised account 0xc49b5e5b9da66b9126c1a62e9761e6b2147de3e1, which had previously been involved in deploying Infini's contracts and held role 0x8e0b. The attacker whitelisted address 0x3ac96134fb0e42a52d33045aee50b89790f05ed0 as the primary receiving address, and drained the Morpho MEVCapital USDC Vault via vulnerable contract 0x9a79f4105a4e1a050ba0b42f25351d394fa7e1dc. Stolen USDC was immediately swapped to DAI via Uniswap across multiple transactions — a deliberate step to circumvent potential USDC blocklisting by Circle. The DAI was then converted to 17,696 ETH at approximately $2,798 per ETH, and transferred to a final holding wallet at 0xfcc8ad911976d752890f2140d9f4edd2c64a6e49. In July 2025, blockchain analytics firm PeckShield flagged that the exploiter's address deposited 5,000 ETH into Tornado Cash and sold 1,770 ETH for approximately $5.88 million at $3,322 per ETH. In August 2025, a further 1,771 ETH was sold at approximately $4,202. After more than 200 days of inactivity, the exploiter's wallet resurfaced in February 2026, purchasing 6,316 ETH at an average price of $2,109 (totaling approximately $13.32 million) before transferring the full balance to Tornado Cash. In total, at least 15,470 ETH — valued at approximately $32.7 million at the time of transfer — was routed through Tornado Cash. No funds have been frozen, seized, or returned as of May 2026.","heading":"On-Chain Evidence","sources":[{"url":"https://www.certik.com/blog/0xinfini-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://www.livebitcoinnews.com/suspected-infini-hacker-routes-32-7m-in-eth-through-tornado-cash/","name":"","type":"other","credibility":3},{"url":"https://crypto.news/infini-exploiter-resurfaces-to-buy-eth-dip/","name":"","type":"other","credibility":3},{"url":"https://www.thecoinrepublic.com/2026/02/09/crypto-news-infini-exploiter-wallet-reappeared-with-ethereum-dip-purchase/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Infini's founder Christian Li responded publicly on X (formerly Twitter) within hours of the exploit becoming known. Li acknowledged personal culpability, stating the team had been 'negligent when transferring the authority before' and accepting ultimate responsibility for the breach. Li pledged to use personal funds to compensate affected users if stolen assets could not be recovered, and stated that user withdrawal functions remained operational. Infini issued a white-hat bounty offer to the attacker: return 80% of the stolen funds within 48 hours and retain 20% (approximately $9.9 million) with no legal consequences. Li subsequently reaffirmed the bounty offer and extended the offer of legal immunity, framing the outreach as a good-faith negotiation. The 48-hour deadline elapsed with no response from the attacker and no return of funds. Infini also stated it was working to coordinate with exchanges and law enforcement to trace and potentially freeze stolen assets. No public arrest, criminal charge, or successful asset freeze had been reported as of May 2026. No regulatory action by the SEC, CFTC, or any other named authority against Infini was found in available sources.","heading":"Team Response","sources":[{"url":"https://defi-planet.com/2025/03/infini-founder-appeals-to-hacker-with-bounty-offer-following-49-5m-heist/","name":"","type":"other","credibility":3},{"url":"https://crypto.news/infini-founder-reaffirms-20-bounty-and-legal-immunity-to-infini-hacker-for-return-of-stolen-funds/","name":"","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2169175","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"As of May 2026, no stolen funds from the February 2025 exploit have been confirmed recovered or returned. The attacker declined the 20% bounty offer within the original 48-hour window and made no public contact with Infini. Subsequent on-chain activity — including routing over 15,470 ETH through Tornado Cash between July 2025 and February 2026 — indicates an active effort to launder and obfuscate the stolen funds rather than return them. Christian Li committed publicly to compensating affected users from personal funds in a worst-case scenario, but no independent verification of whether such compensation was fully disbursed is available in current sources. Infini continued to operate its platform after the exploit, announcing fee reductions and new product features in 2025, which suggests the company did not cease operations. However, the loss of nearly $50 million represents the near-entirety of the platform's pre-exploit TVL, and the long-term financial viability of user reimbursement commitments remains unverified.","heading":"Recovery","sources":[{"url":"https://bitcoinethereumnews.com/ethereum/crypto-hacker-behind-infini-exploit-returns-moves-32m-eth-in-fresh-transfers/","name":"","type":"other","credibility":3},{"url":"https://crypto.news/infini-exploiter-resurfaces-to-buy-eth-dip/","name":"","type":"other","credibility":3},{"url":"https://nairametrics.com/2025/03/04/founder-of-stablecoin-digital-bank-infini-offers-20-bounty-for-return-of-stolen-49-5-million/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Infini exploit illustrates several compounding risk factors that users of the platform should weigh. First, the root cause was not a cryptographic vulnerability but a failure of operational security: a contractor retained privileged access to production smart contracts without the project's knowledge or consent, and the project's leadership failed to audit or revoke these permissions before a significant sum accumulated in the vault. Second, the smart contract involved was deployed as unverified code — meaning its source code was not published on-chain or on a public repository — which prevented independent security review that might have identified the hidden administrative role. Third, the attacker demonstrated deliberate patience and sophistication: the 114-day gap between contract deployment and the attack, the use of Tornado Cash for gas funding before the drain, the immediate USDC-to-DAI swap to frustrate blocklisting, and subsequent active laundering across multiple time periods suggest a planned operation rather than an opportunistic breach. Fourth, the recovered-funds outlook is poor: the attacker has actively used Tornado Cash to launder proceeds and has shown no willingness to negotiate, while on-chain tracking has not resulted in asset freezes. Fifth, Infini's continued operation post-exploit may reflect resilience, but also means users considering the platform today must assess whether compensation commitments were honored and whether the security architecture has been verifiably improved. No independent security audit published post-exploit was identified in available sources. The platform presents a critical historical risk profile due to the scale of the loss, the insider nature of the attack, and the lack of confirmed recovery.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-infini-hack-february-2025","name":"","type":"other","credibility":3},{"url":"https://www.okx.com/en-us/learn/eth-infini-hack-defi-vulnerabilities","name":"","type":"other","credibility":3},{"url":"https://rekt.news/infini-rekt","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-11","event":"Alleged creation of malicious contract by the developer approximately 114 days before the attack; attacker retains role 0x8e0b (privileged admin) over Infini vault contracts after completing contracted work.","source":"","date_original":"2024-11-01"},{"date":"2025-02-24","event":"Attacker funds exploit wallet with 1 ETH from Tornado Cash. Two transactions drain approximately $49.5 million in USDC from the Morpho MEVCapital USDC Vault. Stolen USDC is swapped to DAI on Uniswap and converted to 17,696 ETH (~$49.5M). Funds transferred to wallet 0xfcc8ad911976d752890f2140d9f4edd2c64a6e49. CertiK flags the exploit at 3:18 am UTC.","source":""},{"date":"2025-02-24","event":"Infini founder Christian Li acknowledges the breach on X, accepts personal responsibility, pledges user compensation, and offers the attacker a 20% bounty to return 80% of stolen funds within 48 hours.","source":""},{"date":"2025-02-27","event":"48-hour bounty deadline elapses. Stolen funds remain in attacker's wallet. No contact from the attacker reported.","source":""},{"date":"2025-03","event":"Li publicly reaffirms the 20% bounty offer and extends an offer of legal immunity to the attacker. No response from attacker is reported.","source":"","date_original":"2025-03-01"},{"date":"2025-07","event":"Exploiter's wallet deposits 5,000 ETH into Tornado Cash and sells 1,770 ETH for approximately $5.88 million at $3,322/ETH. PeckShield and CertiK flag the activity.","source":"","date_original":"2025-07-01"},{"date":"2025-08","event":"Exploiter sells a further 1,771 ETH at approximately $4,202/ETH near a local cycle high.","source":"","date_original":"2025-08-01"},{"date":"2026-02-09","event":"After more than 200 days of inactivity, the exploiter's wallet resurfaces, purchasing 6,316 ETH at an average of $2,109 (~$13.32M). The full balance is subsequently transferred to Tornado Cash. At least 15,470 ETH (~$32.7M) has now been routed through Tornado Cash. No funds recovered.","source":""}],"sources_used":[{"url":"https://www.infini.money/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260612115136/https://www.infini.money/","credibility":3,"archive_timestamp":"2026-06-12T11:51:36+00:00"},{"url":"https://www.crypto-reporter.com/newsfeed/infini-launches-global-card-offering-daily-stablecoin-yield-96784/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829045714/https://www.crypto-reporter.com/newsfeed/infini-launches-global-card-offering-daily-stablecoin-yield-96784/","credibility":3,"archive_timestamp":"2026-08-29T04:57:14+00:00"},{"url":"https://cryptoslate.com/neobank-infini-celebrates-50m-tvl-then-suffers-49-5m-exploit-due-to-former-insider/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260316083819/https://cryptoslate.com/neobank-infini-celebrates-50m-tvl-then-suffers-49-5m-exploit-due-to-former-insider/","credibility":3,"archive_timestamp":"2026-03-16T08:38:19+00:00"},{"url":"https://www.certik.com/blog/0xinfini-incident-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725071836/https://www.certik.com/blog/0xinfini-incident-analysis","credibility":3,"archive_timestamp":"2026-07-25T07:18:36+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-infini-hack-february-2025","name":"","type":"other","archive_url":"http://web.archive.org/web/20260727012723/https://www.halborn.com/blog/post/explained-the-infini-hack-february-2025","credibility":3,"archive_timestamp":"2026-07-27T01:27:23+00:00"},{"url":"https://decrypt.co/307513/crypto-neo-bank-infini-50-million-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513190758/https://decrypt.co/307513/crypto-neo-bank-infini-50-million-exploit","credibility":3,"archive_timestamp":"2026-05-13T19:07:58+00:00"},{"url":"https://invezz.com/news/2025/02/24/crypto-neobank-infini-exploited-for-50m-rogue-developer-suspected/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.livebitcoinnews.com/suspected-infini-hacker-routes-32-7m-in-eth-through-tornado-cash/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829050812/https://www.livebitcoinnews.com/suspected-infini-hacker-routes-32-7m-in-eth-through-tornado-cash/","credibility":3,"archive_timestamp":"2026-08-29T05:08:12+00:00"},{"url":"https://crypto.news/infini-exploiter-resurfaces-to-buy-eth-dip/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260306202138/https://crypto.news/infini-exploiter-resurfaces-to-buy-eth-dip/","credibility":3,"archive_timestamp":"2026-03-06T20:21:38+00:00"},{"url":"https://www.thecoinrepublic.com/2026/02/09/crypto-news-infini-exploiter-wallet-reappeared-with-ethereum-dip-purchase/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829091920/https://www.thecoinrepublic.com/2026/02/09/crypto-news-infini-exploiter-wallet-reappeared-with-ethereum-dip-purchase/","credibility":3,"archive_timestamp":"2026-08-29T09:19:20+00:00"},{"url":"https://defi-planet.com/2025/03/infini-founder-appeals-to-hacker-with-bounty-offer-following-49-5m-heist/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829031339/https://defi-planet.com/2025/03/infini-founder-appeals-to-hacker-with-bounty-offer-following-49-5m-heist/","credibility":3,"archive_timestamp":"2026-08-29T03:13:39+00:00"},{"url":"https://crypto.news/infini-founder-reaffirms-20-bounty-and-legal-immunity-to-infini-hacker-for-return-of-stolen-funds/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251217011309/https://crypto.news/infini-founder-reaffirms-20-bounty-and-legal-immunity-to-infini-hacker-for-return-of-stolen-funds/","credibility":3,"archive_timestamp":"2025-12-17T01:13:09+00:00"},{"url":"https://www.chaincatcher.com/en/article/2169175","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829084336/https://www.chaincatcher.com/en/article/2169175","credibility":3,"archive_timestamp":"2026-08-29T08:43:36+00:00"},{"url":"https://bitcoinethereumnews.com/ethereum/crypto-hacker-behind-infini-exploit-returns-moves-32m-eth-in-fresh-transfers/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829023416/https://bitcoinethereumnews.com/ethereum/crypto-hacker-behind-infini-exploit-returns-moves-32m-eth-in-fresh-transfers/","credibility":3,"archive_timestamp":"2026-08-29T02:34:16+00:00"},{"url":"https://nairametrics.com/2025/03/04/founder-of-stablecoin-digital-bank-infini-offers-20-bounty-for-return-of-stolen-49-5-million/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613030658/https://nairametrics.com/2025/03/04/founder-of-stablecoin-digital-bank-infini-offers-20-bounty-for-return-of-stolen-49-5-million/","credibility":3,"archive_timestamp":"2026-06-13T03:06:58+00:00"},{"url":"https://www.okx.com/en-us/learn/eth-infini-hack-defi-vulnerabilities","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829051420/https://www.okx.com/en-us/learn/eth-infini-hack-defi-vulnerabilities","credibility":3,"archive_timestamp":"2026-08-29T05:14:20+00:00"},{"url":"https://rekt.news/infini-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260310100359/https://rekt.news/infini-rekt","credibility":3,"archive_timestamp":"2026-03-10T10:03:59+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:25.32198+00:00","updated_at":"2026-08-30T03:55:00.161988+00:00"}}