A former developer's leftover keys drained $49.5 million from Infini
The stablecoin neobank was not phished or bridged into oblivion. Blockchain sleuths say an engineer who built its contract simply kept admin rights, then used them months later.
On 24 February 2025, Infini — a neobank that issues prepaid cards and pays yield on dollar-stablecoin deposits — lost about $49.5 million in USDC, per PeckShield's assessment as reported by CoinDesk. The theft landed just days after the Bybit hack, in one of the busiest stretches for crypto crime the industry had seen.
What set Infini apart was the method. According to the security firm Cyvers, cited by CoinDesk, the exploit traced to a developer who had helped set up Infini's smart contract and quietly retained administrative rights over it. More than three months later, that access was used to drain the funds. PeckShield identified the attacker as an engineer who originally built the contract, per Candid.technology.
An inside job, on-chain
The trail bore the marks of premeditation. The attacker's wallet had been funded through the mixer Tornado Cash, per CoinDesk, obscuring where the money came from. After the drain, the stolen USDC was converted to DAI and then swapped for 17,696 ETH — worth roughly $2,798 each at the time — using Uniswap, Sky Protocol and 0x, per Candid.technology.
Infini offered the attacker 20% of the stolen assets for returning the rest within 48 hours, delivered as a message written into a blockchain transaction, per CoinDesk. The company's founder maintained that no user private key had been compromised and pledged full compensation in a worst-case scenario, per Candid.technology.
The risk that outlives the contract
Insider exploits are hard to defend against precisely because the access is legitimate. A privileged key that should have been revoked at handover, or transferred to a time-locked multisig, instead sat dormant until someone chose to use it.
- Privileged 'admin' or 'owner' keys are single points of failure; the safest projects revoke them or move control to a time-locked multisig after launch.
- 'No private key was stolen' does not mean no one was robbed — legitimate access, misused, drains funds just the same.
- A yield-paying 'neobank' is only as safe as its smart-contract permissions; ask who can move pooled funds, and how.
- A mixer-funded wallet plus a dormant privileged address are classic pre-attack signatures worth watching for.
For depositors, the lesson is uncomfortable: an audited contract and a polished app say nothing about who still holds the keys behind them. Some of 2025's most damaging losses were not clever code exploits at all — they were trust, left switched on.
— Sources: [CoinDesk](https://www.coindesk.com/markets/2025/02/24/payments-card-issuer-infini-offers-reward-for-return-of-funds-after-usd49-million-exploit) · [Candid.technology](https://candid.technology/infini-stablecoin-bank-usdc-hack/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING