In February 2025, the star project Infini in the crypto payment sector encountered an unexpected storm. This PayFi star, hailed as the 'Web3 Yu'ebao', suffered a raid resulting from internal engineer malfeasance, leading to the theft of nearly $50 million in project funds.

After the incident, Infini's founder Christian immediately stepped up to promise full compensation and emphasized that the platform's withdrawal function was operating normally.

This incident not only plunged Infini into a crisis of trust but also sounded the alarm for security management across the entire crypto industry.

Infini: The 'New Star' in the Crypto Payment Track

Since its inception, Infini has aimed to be the 'next-generation stablecoin digital bank', dedicated to providing users with the convenient experience of 'earning money anytime, anywhere, and paying anytime.' Through virtual cards and the upcoming physical cards, users can use crypto assets in daily consumption while earning daily interest. Infini's card opening fee is waived, the card design is stylish, and combined with collaborations with major crypto communities and KOLs in the Chinese-speaking area, it quickly attracted a large user base.

During the Spring Festival, Infini's launch of the 'On-chain Red Packet' feature gained widespread attention. Users can directly send stablecoin red packets through a link, which sharply contrasts with the red packet features of exchanges like Binance, successfully attracting a large amount of traffic. Although WeChat's built-in browser subsequently blocked Infini's red packet links, this event undoubtedly garnered Infini extensive visibility.

$50 million stolen: Insider Malfeasance, Founder Takes Responsibility

However, just as Infini was gaining momentum, an unexpected security incident plunged the project into crisis. In February 2025, the security firm Certik detected abnormal fund transfers in Infini's Ethereum contract, with approximately $49.5 million being transferred to a wallet funded by Tornado Cash and exchanged for the stablecoin DAI. Subsequently, PeckShield also confirmed this incident, indicating that Infini's private key might have been leaked.

Infini co-founder revealed that the attack was caused by internal engineer malfeasance. Although the related tweets were later deleted, this news undoubtedly shocked Infini's users and partners. Founder Christian quickly responded on the X platform, stating that he was sorting out and tracking the detailed situation and promised full compensation in the worst-case scenario. He also emphasized that his personal private key had not been leaked and that the incident was due to negligence during the transfer of permissions.

Founder Christian: Reputation is More Important than Money

Christian is known for his reputation and accountability in the crypto industry. Previously, during the liquidation turmoil of Curve's founder, he had taken on part of the CRV tokens through OTC to prevent further risk to the Curve ecosystem.

After the Infini incident, Christian once again demonstrated his sense of responsibility. He stated that 70% of the stolen $50 million belonged to major friends he knew, and he has communicated with each of them, promising to bear any potential losses personally. The remaining 30% of the funds will be reinvested into the Infini Vault by next Monday to ensure the platform operates normally.

Christian's quick response and compensation commitment salvaged some trust for Infini. However, this incident also exposed vulnerabilities in Infini's internal management and security controls. Although the founder promised full compensation, rebuilding user trust in the platform will still take time.

Community Response: Support and Doubt Coexist

After the Infini theft incident, the reaction from the crypto community was polarized. On one hand, some community members expressed support for Christian's sense of responsibility. Du Jun, co-founder of ABCDE, even stated he was willing to invest $5 to $10 million to support Infini, saying, 'Losing a bit of money to buy a lesson is better than losing a lot when the project grows.'

On the other hand, some users have questioned Infini's security measures, believing that there are serious issues with the project's private key management and internal permission controls.

Moreover, the Infini incident also impacted the BSC Meme project CHEEMS. As a token holder whale in the CHEEMS community, Christian had previously locked a large amount of CHEEMS tokens to show support for the project. However, following the Infini incident, CHEEMS tokens faced panic selling, and the price dropped significantly. Christian later clarified that compensation would not use CHEEMS funds and expressed confidence in the future of both Infini and CHEEMS.

Industry Warning: Security is the Lifeline of Crypto Projects

The Infini incident once again sounded the alarm for the crypto industry. Whether through external attacks or internal malfeasance, private key management and permission control are core to the security of crypto projects. As OneKey founder Yishi said, 'Maintain a sense of awe for security, do not give yourself a chance to make mistakes, and do not leave loopholes for any internal or external malfeasance.'

This incident also reminds industry practitioners that security is not just a technical issue, but also a management and trust issue. Project teams need to invest more resources in security auditing, permission management, and internal monitoring to ensure the safety of user funds and data.

A temporary fall, can it become a springboard for the future?

The $50 million theft incident of Infini is undoubtedly a heavy blow, but founder Christian's sense of responsibility and quick response salvaged some trust for the project. In the future, whether Infini can rise from the ashes depends on its ability to make substantive improvements in security management and rebuilding user trust.

For the entire crypto industry, this incident once again highlighted the importance of security. Whether in the PayFi track or other crypto fields, only by prioritizing security can true user trust be earned and long-term industry development be promoted. Infini's story may be just an episode in the growth path of the crypto industry, but it undoubtedly sounded the alarm for all practitioners: security is no small matter, and trust is the foundation.

Disclaimer: The content described in this article is for reference only and does not constitute any investment advice. Investors should view cryptocurrency investment rationally based on their own risk tolerance and investment goals, and should not blindly follow the trend.

#infini