How an Attacker Drained $50M from a DeFi Protocol Through Role Escalation
ID: a019f2f2-c955-535e-b6f8-c054ac122000
STIX ID: report--a019f2f2-c955-535e-b6f8-c054ac122000
Feed Name: Check Point Research
This report analyzes two high-impact DeFi incidents: (1) a supply-chain/UI compromise where malicious JavaScript was injected into Safe’s online interface to manipulate multisig transaction parameters during interactions with Bybit’s contract, enabling an attacker to drain roughly $1.4B before removing the code; and (2) an Infini protocol breach where a stolen administrative private key was used to grant REDEEMER_ROLE, register an attacker address, and call a redemption function to exfiltrate ~50M USDC. The write-up includes transaction decoding, exploited contract functions, recommended mitigations (key management, role separation, timelocks, withdrawal limits), and notes a post-attack bounty offer to recover funds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
