logo

How an Attacker Drained $50M from a DeFi Protocol Through Role Escalation 

ID: a019f2f2-c955-535e-b6f8-c054ac122000

STIX ID: report--a019f2f2-c955-535e-b6f8-c054ac122000

Feed Name: Check Point Research

Threat Score
95/100

Date Published: 2025-02-25

Date Updated: 2026-04-27

Author: bferrite

...
...

This report analyzes two high-impact DeFi incidents: (1) a supply-chain/UI compromise where malicious JavaScript was injected into Safe’s online interface to manipulate multisig transaction parameters during interactions with Bybit’s contract, enabling an attacker to drain roughly $1.4B before removing the code; and (2) an Infini protocol breach where a stolen administrative private key was used to grant REDEEMER_ROLE, register an attacker address, and call a redemption function to exfiltrate ~50M USDC. The write-up includes transaction decoding, exploited contract functions, recommended mitigations (key management, role separation, timelocks, withdrawal limits), and notes a post-attack bounty offer to recover funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.