BanklessTimes
image illustrating a hacker
Home Articles Infini Earn Loses $49.5M in Latest DeFi Hack, Inside Job Suspected

Infini Earn Loses $49.5M in Latest DeFi Hack, Inside Job Suspected

David Marsanic
David Marsanic
David Marsanic
Author:
David Marsanic
News writer
February 24th, 2025
Editor:
Joseph Alalade
Joseph Alalade
Editor:
Joseph Alalade
News Lead and Editor
Joseph is a content writer and editor who has actively participated in crypto for over 6 years. He enjoys educating others about Web3 and covering its updates, regulatory developments, and exciting stories.

Before the crypto space could recover from the $1.4 billion Bybit hack, another breach rocked the space. This time, the DeFi platform Infini Earn fell victim to a $49.5 million attack. What’s worse, the hack showed signs of a potential inside job.

On Monday, February 24, hackers exploited the staking service provider Infini Earn protocol, resulting in $49.5 million in losses. Specifically, attackers gained unauthorized access through a compromised private key.

After obtaining the key, the hackers siphoned $49.5 million USDC from the liquidity pool. They then transferred the funds to a new wallet and converted $49.5 million USDC to the DAI stablecoin. Following that, hackers used the wallet to buy 17,696 ETH at $2,798 each and dispersed them across multiple wallets.

Arguably, the most concerning aspect of the incident is the potential for insider involvement. Blockchain security firm Cyvers discovered a trail leading to one of the developers involved in the contract. According to the firm, the developer secretly kept admin rights after delivering the project.

This revelation raises serious questions about potential vulnerabilities in other DeFi protocols. Users also questioned possible North Korean involvement. Notably, the Lazarus Group, the group behind the Bybit hack, previously posed as developers to get privileged access to crypto projects.

Infini Earn Founder Promises to Compensate Users

Following the hack, Infini Earn founder Christian Li expressed regret over the incident. He revealed that his personal wallet wasn’t compromised and conceded he had been negligent.

In any case, he assured users that the protocol has enough liquidity to operate and that users can withdraw their funds normally. He also promised to compensate all hack victims if they fail to recover the funds.

“In the worst-case scenario,” he explained, “full compensation will be paid.”

The Infini Earn hack is the latest high-profile incident after the Bybit exploit, the biggest crypto hack in history. In the Bybit case, North Korean hackers performed a sophisticated phishing attack to target the exchange’s cold wallet.

READ MORE: What We Learned From Bybit Hack: Crypto Beats Banks