QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$43 000 USD
JUNE 2025
GLOBAL
INFRARED FINANCE
DESCRIPTION OF EVENTS
The smart contract in question is at blockchain address 0x4999b48c62d45708809ea8a04516aa09ba3459d5. It was first created on May 18th. TenArmor has speculated that this smart contract is related to Infrared Finance, though no reasoning has been brought forward.
From TenArmor: "It seems that the 0x71561f89() function lacks proper access control and input validation, allowing the attacker to set a malicious contract as an approved vault. Then the attacker can call the useCollateral() function to transfer the collateral pool's funds to the malicious contract."
TenArmor reports that the loss was approximately $43k USD.
It does not appear that Infrared Finance has posted any update or acknowledgement on their Twitter/X account.
It's unclear if the affected protocol is Infrared Finance or may be a copy-cat contract.
It does not appear that the issue was ever publicly addressed by Infrared Finance.
It is unclear which project is related to this smart contract breach, and whether any assistance was provided to affected users.
There are no other posts or analyses relating to this transaction.
A smart contract at address 0x4999b48c62d45708809ea8a04516aa09ba3459d5, created on May 18th, has been linked by TenArmor to a potential exploit involving approximately $43,000 in losses. The exploit reportedly stemmed from inadequate access controls and input validation in the function 0x71561f89(), allowing an attacker to redirect collateral funds to a malicious contract. While TenArmor speculates a connection to Infrared Finance, no direct evidence has been presented, and Infrared Finance has not acknowledged the incident publicly. It remains unclear whether the affected protocol is Infrared Finance or a copycat, and no support or follow-up appears to have been provided to impacted users.
TenArmor Alert - "Our system has detected a suspicious attack involving @InfraredFinance on #BASE, resulting in an approximately loss of $43K." - Twitter/X (Jun 30)
Attack Transaction - BaseScan (Jun 30)
Exploited Smart Contract - BaseScan (Jun 30)
Exploited Smart Contract Creation - BaseScan (Jun 30)
Infrared Finance Vaults (Jun 30)
Infrared Finance Homepage (Jun 30)
