Infini Hacked: Team and Community's Textbook Self-Recovery in 48 Hours
Source: Infini
At around 10:24 AM Beijing time on February 24, 2025, Infini detected abnormal fund movement. Hackers stole funds through an attack and transferred them to the address 0x3ac96134fb0e42a52d33045aee50b89790f05ed0. Subsequently, the attacker quickly converted assets worth approximately 49.5 million US dollars into DAI, ETH, and further transferred the exchanged ETH to the address 0xfcc8ad911976d752890f2140d9f4edd2c64a6e49.
Following the event, the Infini team took immediate emergency response measures, including:
1. Conducting a thorough investigation to track the fund flow and collaborating with security agencies and relevant partners.
2. Proactively reaching out to affected clients, providing accurate information on the situation, and ensuring that clients' interests are safeguarded.
3. Emergency fund allocation to ensure all client withdrawal requests can be processed normally.
As of 6:00 PM Beijing time on February 26, 2025, the stolen funds are still held in the above-mentioned address, with no further signs of transfer. The Infini platform is operating as usual, and all client withdrawal requests have been fulfilled. The security team is actively tracking the fund flow and cooperating with all parties to recover the losses to the fullest extent.
With the collective efforts of the team, Infini has temporarily overcome this crisis. Infini will continue to strengthen its security measures to protect user assets and will provide timely updates to the community on progress.
Infini Incident Timeline
Due to Infini's robust internal fund monitoring system, the team responded quickly to the incident, minimizing losses and impacts:
Within 30 Minutes of the Incident
· The Infini internal team promptly detected abnormal fund movement, swiftly locked the suspicious account, and traced the attack path based on on-chain data.
1 Hour After Incident
· Project founder Christian and co-founder Christine made a full refund commitment on major social media and user communities to ensure the safety of user assets.
· The team swiftly transferred $5 million of their own funds to inject into the Cobo Wallet to ensure timely response to all user withdrawal requests.
· Blockchain security company SlowMist intervened in the investigation and confirmed that the attacker has a high level of technical expertise, providing initial analysis of the attack method.
2 Hours After Incident
· Founder Christian publicly stated that the event was not due to a private key leak but due to negligence in the custody transfer process, reiterating the full refund commitment.
6 Hours After Incident
· On-chain security analyst ZachXBT posted on Platform X, pointing out that the stolen funds were not fully liquidated within 40 minutes, while questioning the delayed intervention of USDC issuer Circle.
· Cyvers Alerts monitoring indicated that the hacker exploited a historical permission management vulnerability, secretly retaining contract administrator privileges and launching the attack.
12 Hours After Incident
· Infini's official team made a public proposal to the hacker, offering a 20% bounty as a reward in exchange for the return of the stolen funds.
24 Hours After Incident
· Over 98% of affected users have been contacted, and all user withdrawal requests have been addressed.
48 Hours After Incident
· The Infini team continues to optimize security measures, transferring core funds to the most secure Cobo Wallet to ensure normal operation of payment, transfers, withdrawals, and all other business functions.
· Internal emergency response within the office continues, with team members analyzing on-chain data overnight, closely cooperating with the security company and law enforcement agencies to ensure smooth progress of the investigation.
· Currently, Infini is actively assisting law enforcement and conducting a judicial investigation and on-chain fund tracing in collaboration with the blockchain security company SlowMist, with significant progress already made. Infini will provide a full report and event explanation to the community once the investigation is completed.
Latest Progress and Future Plans of the Infini Project
It is noteworthy that despite facing a security incident, the core features of the Infini project have remained operational, and both development and operations have been unaffected:
· The release of the Physical Card with Apple Pay support is proceeding as planned.
· The daily yield mechanism is expected to be optimized within the next 3-4 weeks to ensure the highest level of security for the Yield component.
· On-chain data indicates that despite some TVL fluctuations post-incident, the growth trend of new deposit addresses (new users) remains stable, demonstrating continued market confidence in Infini.
· The community's support for Infini is strong, with minimal negative sentiments on social media, and community members widely acknowledging the team's response measures and solutions.
Special Thanks
During this incident, Infini has received wide support and goodwill from both within and outside the industry. ABCDE's co-founder, Du Jun, has expressed willingness to provide a funding support of $5 to $10 million to assist in the stable operation of the Infini platform. Additionally, several industry KOLs have publicly voiced their support for Infini, praising its transparency and crisis management capabilities.
Infini expresses sincere gratitude for this support, especially from the community, users, and industry partners for their understanding and backing. The team is committed to continue giving their all to ensure the platform's security and stability, and to provide users with high-quality financial services.
Below are some voices from industry KOLs. The number of voices is substantial, and only a selection can be presented here:


You may also like

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Apollo and Blackstone Reportedly Back $35 Billion Anthropic Chip Financing as Deal Details Remain Unclear
On June 9, according to currently available news alerts, Apollo and Blackstone Group participated in a $35 billion financing for an Anthropic “chip project.” Based on the original wording of the report, the funding has already been raised, but public information remains limited. The financing structure, use of proceeds, project entity, and whether Apollo and Blackstone participated through equity, debt, or project financing have not yet been disclosed.

Humanity Protocol Security Incident Escalates: More Than $31 Million Stolen From Related Addresses as Attacker Continues Selling H for ETH
On June 9, according to monitoring by Onchain Lens, more than $31 million has been stolen from addresses linked to Humanity Protocol, and the attack is still ongoing, with the hacker continuously swapping H tokens for ETH. Project founder Terence Kwok later confirmed the security incident on X, saying the issue involved a private key leak.

Bloomberg: As Bitcoin Weakens, Stablecoins and RWA Continue to Drive Expansion in Crypto Businesses
In June, Bloomberg reported that despite Bitcoin falling below $60,000 last week, wiping out about $235 billion in market value within seven days, and dropping close to 50% from last year’s peak, some core businesses in the crypto industry are still expanding, mainly in stablecoins, real-world asset tokenization (RWA), payments, and infrastructure. The report also noted that overall altcoin activity has contracted significantly: altcoin market capitalization has fallen from a peak of about $431 billion in November 2021 to around $170 billion, and among the tens of millions of tokens issued in recent years, fewer than 1,700 still maintain meaningful trading activity.

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?

Binance Research: RWA Market Expected to Expand Nearly 6x from Early 2025, with Public Equities and Onchain Payments Heating Up Together
In June, Binance Research said in its monthly market report that the real-world asset (RWA) market is expected to grow by about 589% from the beginning of 2025. Bond- and money market fund-related RWA expanded by about $6.5 billion, up 83% year over year, while publicly traded equity RWAs grew by about 422%. The report also noted that monthly crypto debit card transaction volume exceeded $747 million in May, up 48.6% year to date.

Japan to Assess a Framework for Yen Stablecoins and Crypto ETFs as Asia’s Compliant Payments Narrative Heats Up
Recently, according to the original report, Japan is considering the launch of yen stablecoins and cryptocurrency ETFs. Public information remains limited at this stage, and there is still no complete policy text, regulatory draft, or clear implementation timeline, so this is better characterized as a “policy discussion” rather than formal implementation. The original wording also noted that advancing stablecoin regulation in Asia is driving XRP usage and supporting growth in the XRPL ecosystem. However, based on currently available public information, there is not enough evidence to directly establish a clear causal relationship between this round of discussion in Japan and XRP or XRPL.

ZachXBT: Humanity private key leak and abnormal surge in H token should be viewed separately
On June 9, according to related disclosures, on-chain investigator ZachXBT posted an update on Humanity’s roughly $31 million security incident, saying that after further analyzing fund flows, he currently tends to believe the project team was not involved in an “inside job” or a self-staged attack. According to him, the official explanation about the private key leak was broadly accurate, but before the token unlock, the price of H had been artificially pushed higher, and the hacker later took advantage of that market environment; therefore, the private key leak and the earlier abnormal price pumping should be regarded as two separate and independent events. This reframing has shifted the market’s understanding of the nature of the incident. Earlier discussion around Humanity had focused on whether the team directly participated in the attack or used the security incident to cover up internal operations. ZachXBT’s latest remarks shift the focus from “whether it was self-theft” to “whether there were pre-unlock market structure issues.” He also questioned whether the team may have.

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing

Morning Report | BitMine increased its holdings by 126,971 ETH last week; trader Eugene announced his exit from the crypto market

Wang Chuan: How can one not feel anxious after the neighbor Old Wang made thirty times profit by investing in storage stocks? (Seven) - A quarter-century cycle

Cryptocurrency CEXs are flocking to sell US stocks, and traditional brokerages are facing an "uninvited guest."

$75 billion in foreign capital has fled, and South Korean retail investors have absorbed it all using leverage

Japan’s Three Megabanks Plan Joint Stablecoin Issuance in Fiscal 2026
MUFG, SMBC, and Mizuho reportedly plan to jointly issue fiat-pegged stablecoins in fiscal 2026, signaling Japan’s growing push into bank-led digital payment infrastructure.

Humanity Discloses H Token Dual-Chain Attack Details, With Losses on Ethereum and BSC Exceeding $36 Million
Humanity said the H token attack across Ethereum and BSC caused more than $36 million in losses after leaked ProxyAdmin keys enabled malicious contract upgrades and token minting.

White House Discusses CLARITY Act With Law Enforcement Ahead of Senate Vote
The White House discussed the CLARITY Act with law enforcement ahead of a Senate vote, focusing on illicit finance risks and developer protections.

Bitcoin Trading Guide 2026: Strategies for Experienced Traders
Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI
Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention
Apollo and Blackstone Reportedly Back $35 Billion Anthropic Chip Financing as Deal Details Remain Unclear
On June 9, according to currently available news alerts, Apollo and Blackstone Group participated in a $35 billion financing for an Anthropic “chip project.” Based on the original wording of the report, the funding has already been raised, but public information remains limited. The financing structure, use of proceeds, project entity, and whether Apollo and Blackstone participated through equity, debt, or project financing have not yet been disclosed.
Humanity Protocol Security Incident Escalates: More Than $31 Million Stolen From Related Addresses as Attacker Continues Selling H for ETH
On June 9, according to monitoring by Onchain Lens, more than $31 million has been stolen from addresses linked to Humanity Protocol, and the attack is still ongoing, with the hacker continuously swapping H tokens for ETH. Project founder Terence Kwok later confirmed the security incident on X, saying the issue involved a private key leak.
Bloomberg: As Bitcoin Weakens, Stablecoins and RWA Continue to Drive Expansion in Crypto Businesses
In June, Bloomberg reported that despite Bitcoin falling below $60,000 last week, wiping out about $235 billion in market value within seven days, and dropping close to 50% from last year’s peak, some core businesses in the crypto industry are still expanding, mainly in stablecoins, real-world asset tokenization (RWA), payments, and infrastructure. The report also noted that overall altcoin activity has contracted significantly: altcoin market capitalization has fallen from a peak of about $431 billion in November 2021 to around $170 billion, and among the tens of millions of tokens issued in recent years, fewer than 1,700 still maintain meaningful trading activity.
