<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft</id>
	<title>Infini Money Anonymous Developer Backdoor Vault Theft - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;action=history"/>
	<updated>2026-04-19T16:51:30Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;diff=6574&amp;oldid=prev</id>
		<title>Azoundria: COMPLETE 30 minutes. Reviewed, substantially improved, and sourced the introduction paragraph. Moved post-incident information from reality section to technical details. Added sources and fixed typos in the timeline. Added description for quote in immediate reactions section. Filling in more detailed information on losses and recovery. Spreading around the sources to different article sections. Completed an initial prevention section with policies for individuals, platforms, and regulators.</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;diff=6574&amp;oldid=prev"/>
		<updated>2025-03-06T00:42:01Z</updated>

		<summary type="html">&lt;p&gt;COMPLETE 30 minutes. Reviewed, substantially improved, and sourced the introduction paragraph. Moved post-incident information from reality section to technical details. Added sources and fixed typos in the timeline. Added description for quote in immediate reactions section. Filling in more detailed information on losses and recovery. Spreading around the sources to different article sections. Completed an initial prevention section with policies for individuals, platforms, and regulators.&lt;/p&gt;
&lt;a href=&quot;https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;amp;diff=6574&amp;amp;oldid=6565&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;diff=6565&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/infinimoneyanonymousdeveloperbackdoorvaulttheft.php}} {{Unattributed Sources}}  Infini Money Logo/HomepageInfini Money, a crypto payment solution, suffered a major exploit when a rogue developer retained admin privileges and drained $49.5 million from the platform. The hacker used the access to steal USDC, swapped it for DAI, and laundered it through Tornad...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Infini_Money_Anonymous_Developer_Backdoor_Vault_Theft&amp;diff=6565&amp;oldid=prev"/>
		<updated>2025-03-03T22:18:29Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/infinimoneyanonymousdeveloperbackdoorvaulttheft.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Infinimoney.jpg&quot; title=&quot;File:Infinimoney.jpg&quot;&gt;thumb|Infini Money Logo/Homepage&lt;/a&gt;Infini Money, a crypto payment solution, suffered a major exploit when a rogue developer retained admin privileges and drained $49.5 million from the platform. The hacker used the access to steal USDC, swapped it for DAI, and laundered it through Tornad...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/infinimoneyanonymousdeveloperbackdoorvaulttheft.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Infinimoney.jpg|thumb|Infini Money Logo/Homepage]]Infini Money, a crypto payment solution, suffered a major exploit when a rogue developer retained admin privileges and drained $49.5 million from the platform. The hacker used the access to steal USDC, swapped it for DAI, and laundered it through Tornado Cash. Despite Infini's founder, Christian, acknowledging his mistake and pledging to cover the losses, including offering a 20% bounty for the return of funds. The hacker ignored the offer. The Infini Money project continues to operate with decreased confidence, and it appears that fund losses have been limited to the project investors. It appears that Christian remains on the hook for the loss personally.&amp;lt;ref name=&amp;quot;rektnews-18167&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;transfer1eth-18168&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lookonchaintweet-18169&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;yieldsandmoretweet-18170&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinilinktree-18171&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinihomepage-18172&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinichristiantweet-18173&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinitwitternote-18174&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinitwitteroffer-18175&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinioperationupdate-18176&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;firstthefttx-18177&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;secondthefttx-18178&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;infinitwitter-18179&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;transferwallets-18180&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Infini Money ==&lt;br /&gt;
Infini Money is a crypto payment solution designed for the masses, allowing users to make instant crypto payments globally with the Infini Card. It offers daily interest on balances, democratizing access to premium yield opportunities without requiring a physical card. Infini Card users can pay at over 100 million merchants worldwide, both online and offline, using their digital assets, with compatibility for platforms like Apple Pay, Google Pay, and AliPay. Infini emphasizes security, with audited smart contracts and a licensed custody partner, Cobo, ensuring asset protection. The service is globally accessible, free of monthly or annual fees, and includes a virtual card, with a physical card launching soon.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
Beneath the technical jargon and blockchain complexity lies a disappointingly simple truth about Infini's collapse.&lt;br /&gt;
&lt;br /&gt;
A complete lack of basic access control hygiene. No mandatory privilege transfers. No time-based access expirations. No multi-signature requirements for critical functions.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
An anonymous developer who helped to develop the Infini smart contract appears to have retained control, and used this control to withdraw $49.5m USDC of investor funds from the smart contract.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Infini Money Anonymous Developer Backdoor Vault Theft&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 5:57:47 PM MST&lt;br /&gt;
|Initial TornadoCash Withdrawal&lt;br /&gt;
|The attacker withdraws one ETH from TornadoCash.&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 7:15:59 PM MST&lt;br /&gt;
|Both Theft Transactions&lt;br /&gt;
|The first theft transaction steals 11,455,666.712564 USDC from the smart contract. The second theft transaction (in the same block) steals 38,060,996.264534 USDC from the smart contract. In the same block, the 49516662.977098 USDC is swapped for 49,516,662.977 DAI.&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 8:40:59 PM MST&lt;br /&gt;
|Funds To Second Address&lt;br /&gt;
|Stolen funds start to be moved by the hacker to a second Ethereume wallet address.&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 8:44:00 PM MST&lt;br /&gt;
|LookOnChain Tweet Made&lt;br /&gt;
|LookOnChain first spotted the anomaly, “A newly created wallet spent 49.5M $DAI to buy 17,696 $ETH at $2,798 in the past hour.”&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 8:53:00 PM MST&lt;br /&gt;
|yieldsandmore Announcement&lt;br /&gt;
|yieldsandmore posts an announcement on Twitter/X where they believe that the Infini smart contract address was hacked into a tornado-sourced address.&lt;br /&gt;
|-&lt;br /&gt;
|February 23rd, 2025 9:48:00 PM MST&lt;br /&gt;
|Christian Post On Twitter/X&lt;br /&gt;
|Christian posts on Twitter about the recent security issue, reflecting on a previous comment made by a friend about how smooth his journey has been. He admits that after the incident with Bybit, the next issue came unexpectedly from his own situation. Christian clarifies that his private key was not compromised, but a mistake occurred during the delegation of permissions, ultimately making it his responsibility. He expresses gratitude for the support from friends, assures that liquidity is not a problem, and promises full compensation while investigating the funds. He apologizes for causing worry and acknowledges that rebuilding trust will be challenging, but they won't give up.&lt;br /&gt;
|-&lt;br /&gt;
|February 24th, 2025 3:36:00 AM MST&lt;br /&gt;
|Infini Releases Statement&lt;br /&gt;
|Infini releases a statement on Twitter/X addressing reports of a security breach. They express regret for the concern caused and assure users that their team is actively investigating and securing all systems. The company confirms that all transfers, deposits, withdrawals, and payments are functioning normally. Despite the issue, Infini reaffirms its commitment to its vision of becoming a crypto neo bank and encourages continued progress.&lt;br /&gt;
|-&lt;br /&gt;
|February 24th, 2025 7:22:00 AM MST&lt;br /&gt;
|Bounty Offered To Hacker&lt;br /&gt;
|The Infini team offers the hacker a 20% bounty in exchange for not pursuing further. They claim to have &amp;quot;critical IP and device information&amp;quot; regarding the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|February 25th, 2025 7:58:00 AM MST&lt;br /&gt;
|Fund And Operation Update&lt;br /&gt;
|Infini shares an update with their community regarding the status of funds and operations. They confirm that Infini's funds are securely stored in the Cobo Custodian Wallet. All Infini Card functions, including transfers, deposits, withdrawals, and payments, remain fully operational. The team is focused on securing the Infini Earn feature, with an estimated 3-4 week timeline to resolve the issue, during which yield distribution will be paused. Infini is actively working with legal authorities and the @SlowMist_Team on the investigation, with progress being made. They thank the community for their patience and support, emphasizing that tough times don't last, but tough people do.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
The Infini situation ended in a major exploit where the platform lost $49.5 million due to a rogue developer who maintained admin privileges after completing their work. The hacker, who had patiently waited for months, drained funds from Infini’s vault using privileged access, then laundered the stolen funds through Tornado Cash, converting them to ETH.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Just blind trust in a faceless developer who built a backdoor, bided their time, and struck when the vault was fattest.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
11,455,666.712564 + 38,060,996.264534 = 49516662.977098 or 49517k USDC&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $49,517,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;A friend once joked that I had been having too smooth sailing along the way. I said that I was always ready for the first disaster, but I didn’t expect that I would be the one to run into trouble right after bybit.&lt;br /&gt;
&lt;br /&gt;
My personal private key has not been leaked, so there is no need to worry too much. I was negligent when transferring the authority before. It is ultimately my responsibility. This has sounded the alarm.&lt;br /&gt;
&lt;br /&gt;
Thank you friends for your voice and support. There is no problem with liquidity. Full compensation can be paid and the funds are being traced.&lt;br /&gt;
&lt;br /&gt;
I'm sorry to have worried everyone who trusted us. I know rebuilding trust will be a difficult process, but we won't give up.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
Infini's founder, Christian, acknowledged his mistake in transferring authority to the developer and pledged to personally cover the losses, especially for significant investors. Despite his efforts, including offering 20% of the stolen amount for the return of funds, the situation ended in a loss for Infini. Many lessons have been highlighted including the importance of proper access control and security protocols. Industry analysts note a hard lesson about the risks of placing too much trust in developers.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
The hacker continues to move and swap funds around, and appears to have no intention of engaging with the bounty offered.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-18167&amp;quot;&amp;gt;[https://rekt.news/infini-rekt/ Rekt - Infini - Rekt] (Accessed Feb 28, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;transfer1eth-18168&amp;quot;&amp;gt;[https://etherscan.io/tx/0x03db8172ada9778e168fb1903d513782161d3e63a57004244d9437de89c68741 Transfer Of 1 ETH From TornadoCash To Hacker] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;lookonchaintweet-18169&amp;quot;&amp;gt;[https://twitter.com/lookonchain/status/1893869666717585756 LookOnChain - &amp;quot;A newly created wallet spent 49.5M $DAI to buy 17,696 $ETH at $2,798 in the past hour.&amp;quot; - Twitter/X] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;yieldsandmoretweet-18170&amp;quot;&amp;gt;[https://twitter.com/yieldsandmore/status/1893871757666275587 yieldsandmore - &amp;quot;Seems like $50m of @0xinfini Earn Funds just got hacked, into Torn-sourced addy 0x3ac96134fb0e42a52d33045aee50b89790f05ed0. Funds were taken from Morpho MEVCapital Usual USDC Vault.&amp;quot; - Twitter/X] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinilinktree-18171&amp;quot;&amp;gt;[https://linktr.ee/0x.infini Infini Linktree] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinihomepage-18172&amp;quot;&amp;gt;[https://www.infini.money/ Infini Money Homepage] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinichristiantweet-18173&amp;quot;&amp;gt;[https://twitter.com/Christianeth/status/1893885666557411712 Christian - &amp;quot;A friend once joked that I had been having too smooth sailing along the way. I said that I was always ready for the first disaster, but I didn’t expect that I would be the one to run into trouble right after bybit.&amp;quot; - Twitter/X Translation] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinitwitternote-18174&amp;quot;&amp;gt;[https://twitter.com/0xinfini/status/1893973307596435871 Infini Money - &amp;quot;We're aware of reports on a security compromise affecting Infini. We're deeply sorry for the concern this causes - our team is working around the clock to investigate and secure all systems at the moment.&amp;quot; - Twitter/X] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinitwitteroffer-18175&amp;quot;&amp;gt;[https://twitter.com/0xinfini/status/1894030200490315887 Infini Money - &amp;quot;We’ve identified critical info regarding the exploit and we’re monitoring involved addresses.&amp;quot; - Twitter/X] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinioperationupdate-18176&amp;quot;&amp;gt;[https://twitter.com/0xinfini/status/1894401496508502099 Infini Money - &amp;quot;All Infini Card functions—transfers, deposits, withdrawals, and payments—are fully operational.&amp;quot; - Twitter/X] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;firstthefttx-18177&amp;quot;&amp;gt;[https://etherscan.io/tx/0xacf84c5944f662a4fcf783806993d713a150994932008e72e4e47a58d6665f7f Transfer Of 11,455,666.712564 USDC From Infini To Hacker] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;secondthefttx-18178&amp;quot;&amp;gt;[https://etherscan.io/tx/0xecb31ff694c0e6c5e5b225c261854c0749ecf5d53c698fcda61f2d8e3db8f9fc Transfer Of 38,060,996.264534 USDC From Infini To Hacker] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;infinitwitter-18179&amp;quot;&amp;gt;[https://twitter.com/0xinfini 0xInfini Twitter] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;transferwallets-18180&amp;quot;&amp;gt;[https://etherscan.io/tx/0xd9796b6a4dc6c32f5b9599407dabac58e5c5f2efa9a96f7b32ec254d6335fa04 Transfering ETH Funds To New Wallet By Hacker] (Accessed Mar 3, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>