ChainBleedv0.1 · open intel
← back to feed·ETHLOGIC2025-02-24 · 1y ago
Incident · DEFILLAMA

Infini

Dev Privilege Oversight Exploit
Estimated loss
$49.50M
VERDICT —CONFIG LAYER
No source-code logic bug — the contract worked exactly as written. The failure lived in the off-chain handover process: role enumeration (RoleGranted/RoleRevoked log scan) at deploy time would have shown the dev EOA still held the privileged role. This is precisely the audit's Invariant 9 (role enumeration) territory.
▰ METHOD
Dev Privilege Oversight Exploit
LOGICBYTECODE CATCHABLEAI SCANNABLE
Root cause

Infini's USDC vault contract on Ethereum used role-based access control where a privileged role (later identified by its role hash `0x8e0b...`) could call a transferFunds-class function that moved the entire vault balance to an arbitrary recipient. That role was granted during deployment to an EOA controlled by a third-party contract developer who had built the initial version of the vault months earlier. After delivery the team migrated operational ownership to a multisig but never called revokeRole / renounceRole on the original developer's address — the role assignment persisted in the proxy's storage. On 2025-02-24 the developer (or someone with access to that EOA's key) signed a single transaction calling the privileged withdraw path and moved 49.5M USDC to an attacker-controlled address, which immediately swapped to DAI then ETH and laundered through Tornado Cash. The vault contract itself was not exploited; the access-control configuration was.

Forensic narrative

Classification: Protocol Logic. Technique: Dev Privilege Oversight Exploit. Target type: DeFi Protocol. Affected chains: Ethereum.

Primary source
https://rekt.news/infini-rekt
Sourced from
DefiLlama Hacks dataset · api.llama.fi/hacks
Technical record
chain
ethereum
protocol
Infini
bug_class
logic
date_occurred
2025-02-24
loss_usd
$49,500,000
classification
Protocol Logic
technique
Dev Privilege Oversight Exploit
target_type
DeFi Protocol
source_id
dl:adhoc:infini:1740355200
Related — same bug class· logic
2026-05-13
28d ago
TRON
Transit Finance
Deprecated Smart Contract Exploit
logic
$1.88M
UNRATED
2026-05-13
28d ago
ETH
TAC Cross-Chain Layer (TON Side)
Contract Vulnerability
logic
$2.80M
UNRATED
2026-05-13
28d ago
ETH
Transit Finance
Contract Vulnerability
logic
$1.88M
UNRATED
2026-05-12
29d ago
ARB
Aurellion
Uninitialized Proxy Exploit
logic
$456.0K
UNRATED
2026-05-12
29d ago
BSC
SQ Protocol
Acces Control Exploit
logic
$346.0K
UNRATED
2026-05-12
29d ago
BSC
SQ Protocol
Contract Vulnerability
logic
$346.1K
UNRATED
ChainBleed — live web3 threat intelligence