Infini contract attack incident
The Infini contract was attacked, with stolen funds exceeding 49 million dollars, and continuous tracking of subsequent developments.
22:26 Infini: Key information about the vulnerability has been identified, and the involved addresses are being monitored
ChainCatcher message, Infini has updated the progress of the hacking incident on platform X, disclosing that key information regarding the vulnerability has been identified and that the involved addresses are being monitored.
22:15 Infini founder: If the hacker returns the funds, willing to offer 20% of the amount as a reward
ChainCatcher message, stablecoin digital bank Infini founder Christian posted on social media, "I know hackers may be monitoring my tweets, so this is my sincere message: I have tried to show that there are still good and responsible people in this industry. I deeply regret my mistakes and will strive to do the right thing for my users.I hope there is a way to recover what we have lost, and I am willing to offer 20% of the stolen amount as a bounty, and I promise that if the funds are returned, I will not take legal action. Regardless, I will continue to love and support this industry."
18:47 Infini: The team is investigating and protecting all systems around the clock, and functions such as deposits and withdrawals are operating normally
ChainCatcher message, the stablecoin digital bank Infini announced that, "We are aware of reports regarding a security vulnerability affecting Infini. We sincerely apologize for the concerns this has caused, and the team is currently investigating and securing all systems around the clock.All transfers, deposits, withdrawals, and payments remain normal and operational."
18:09 ZachXBT questions Circle's failure to respond promptly after the Infini attack incident
ChainCatcher news, on the X platform, on-chain security analyst ZachXBT stated that in the attack incident involving the crypto payment company Infini, the stolen 50 million USDC was not fully cashed out within 40 minutes.However, Circle, the issuer of USDC, failed to respond promptly during this period, and its claimed "24/7 incident response team" did not intervene in a timely manner.
17:10 Infini founder: It will take some time to upgrade and restart the business, which will be carried out under the premise of ensuring absolute safety of funds
ChainCatcher message, according to Infini founder Christian's post on X, "Of the 50 million dollars stolen, seventy percent belongs to large friends I know personally. I have already communicated with each of them and will personally bear the possible losses and settle privately. The remaining funds will be reinvested into the infini vault before next Monday, and everything will continue as usual. The funds are ready, and I will respond to any withdrawal requests in the meantime, so please rest assured.I apologize for the need for some time to upgrade and restart the business; everything will proceed under the premise of ensuring the absolute safety of the funds."
15:33 Infini founder: Since the theft, withdrawal requests have accumulated to 500,000 USD, all of which have been responded to
ChainCatcher message, Infini founder Christian tweeted that since the theft, the total withdrawal requests have accumulated to $500,000, all of which have been responded to, and many wallets continue to deposit money.Currently, all product consumption and withdrawals are proceeding as usual, the only affected part is the wealth management section (because the contracts have been suspended and no further fund transfers are made to prevent secondary risks), which will require some time to propose and implement a more appropriate solution.
14:15 Cyvers Alerts: Infini was attacked due to hackers secretly retaining administrative privileges
ChainCatcher message, according to Cyvers Alerts monitoring, the attack on Infini was due to hackers secretly retaining administrative privileges.The hackers operated from 0xc49b5e5b9da66b9126c1a62e9761e6b2147de3e1, which was originally developed as part of the Infini project for this contract. However, after the project was delivered, they secretly retained the admin privileges.
13:32 Infini Founder: Currently, withdrawals are normal; first, use personal funds to cover
ChainCatcher message, Infini founder Christian stated in the community that withdrawals are currently normal, and personal funds will be used to cover first.
12:56 Infini founder: The personal private key was not leaked; there was negligence during the transfer of permissions
ChainCatcher message, Infini founder Christian tweeted: "A friend joked before that my journey has been too smooth, and I said I was always ready to face the first disaster. I didn't expect that after bybit, the next incident would be myself. The personal private key was not leaked; it was a negligence during the transfer of permissions. Ultimately, it is my own responsibility, and this has sounded the alarm. Currently, there are no issues with liquidity, and we can make full compensation. We are investigating the funds."
12:47 Slow Fog Cosine: Infini hackers stole nearly $50 million in two incidents
ChainCatcher message, SlowMist's cosine monitoring, Infini hackers are very skilled in technology and understand smart contract operations, which is why they could steal funds from its Vault and related strategies with a private key, stealing twice:11,455,666 USDChttps://etherscan.io/tx/0xacf84c5944f662a4fcf783806993d713a150994932008e72e4e47a58d6665f7f38,060,996 USDChttps://etherscan.io/tx/0xecb31ff694c0e6c5e5b225c261854c0749ecf5d53c698fcda61f2d8e3db8f9fc