On February 24, 2026, stablecoin neobank Infini was drained of $49.5 million by a former developer who had quietly retained administrative privileges over the protocol's smart contracts for more than three months after deployment. The attacker converted the stolen USDC to DAI, purchased 17,696 ET...
"The real threat was people, not code. Passwords, keys, compromised devices, manipulated employees — human error, not broken code." — Mitchell Amador, CEO, Immunefi
On February 24, 2026, stablecoin neobank Infini was drained of $49.5 million by a former developer who had quietly retained administrative privileges over the protocol's smart contracts for more than three months after deployment. The attacker converted the stolen USDC to DAI, purchased 17,696 ETH, and routed the proceeds through Tornado Cash — a textbook exit by an insider who had been sitting on a backdoor the entire time.
The Infini exploit is not an isolated incident. It is the latest in a cascade of access-control failures that have defined crypto's security landscape since the $1.5 billion Bybit hack of February 2025. Across 2025, roughly $17 billion in crypto was lost to hacks, scams, and fraud — and the majority of those losses stemmed not from broken smart contracts but from compromised humans, misconfigured permissions, and retained privileges. February 2026 alone has already produced at least $54 million in losses from access-control and configuration failures across Infini, CrossCurve, and Moonwell. DeFi's existential security problem is no longer about code. It is about who holds the keys.
Infini, a Hong Kong-based stablecoin neobank offering yield-bearing USDC products, was exploited on February 24, 2026 when a former contract developer leveraged a hidden administrative role to drain the protocol's Morpho MEV Capital Usual USDC Vault.
The technical mechanism was straightforward. When the developer originally deployed Infini's smart contracts, they embedded a privileged role (identifier 0x8e0b) that granted unrestricted withdrawal authority over the protocol's vault. This role was assigned to a blockchain address the developer controlled. After the contract was deployed and the protocol went live, the developer's access was never revoked. More than three months later, the developer activated the backdoor.
The attacker's wallet had been pre-funded through Tornado Cash, indicating premeditation. After draining $49.5 million in USDC, the attacker converted the stablecoins to DAI (to avoid USDC's centralized freeze mechanism), then purchased 17,696 ETH at approximately $2,800 per token.
Infini's founder, Christian Li, took personal responsibility for the breach, admitting he had failed to properly transfer authority away from the developer after deployment. He pledged to cover the full $49.5 million loss from personal funds — noting that 70% of the stolen assets belonged to institutional investors — and offered the hacker a 20% bounty ($9.9 million) plus legal immunity for the return of the remaining funds.
The Infini case exposes a fundamental governance failure: the protocol had no multi-signature requirement on its most critical administrative function. A single compromised or malicious key holder could — and did — drain the entire treasury.
Infini was not alone. February 2026 has produced a concentrated cluster of access-control and configuration failures:
CrossCurve Bridge — $3 Million (February 2): The cross-chain liquidity protocol's ReceiverAxelar contract contained a gateway validation bypass. Attackers forged cross-chain messages to call the contract's expressExecute function, bypassing gateway verification and triggering unauthorized token unlocks across multiple chains. Ten wallets were identified as recipients. The root cause was insufficient access validation on a critical bridge function — the contract trusted message authenticity without properly verifying the sender.
Moonwell Oracle — $1.78 Million (February 15): A governance proposal (MIP-X43) activated Chainlink OEV wrapper contracts on Base and Optimism with a misconfigured oracle that priced Coinbase Wrapped ETH (cbETH) at approximately $1.12 instead of its actual value of roughly $2,200. The configuration error used only the cbETH/ETH exchange rate rather than multiplying it by the ETH/USD price feed. Liquidators seized collateral for pennies on the dollar, creating $1.78 million in bad debt across 1,096 cbETH positions. The pull request for the configuration change listed an AI model as co-author, fueling debate over "vibe coding" in production DeFi infrastructure.
Arbitrum Governance Account Compromise (February 2026): The official X account for Arbitrum Governance was compromised, with attackers posting malicious links. While no direct financial loss was reported, the incident demonstrated that even governance-layer communications channels are vulnerable to social engineering.
These incidents share a common thread: the failure point was not the cryptographic security of the blockchain itself, but the human and operational layers surrounding it — developer access policies, configuration review processes, and social media account security.
The February 2026 incidents are data points in a much larger trend. According to Chainalysis, crypto theft reached $3.4 billion in 2025, with North Korean state-sponsored groups responsible for $2.02 billion — a 51% year-over-year increase. The Bybit hack alone accounted for $1.5 billion.
But the headline figure understates the problem. When including scams, fraud, and social engineering, total crypto losses in 2025 reached approximately $17 billion, according to CoinDesk's analysis. The critical finding: the majority of these losses stemmed from Web2-style operational failures, not on-chain code exploits.
The data is stark:
| Attack Vector | Share of 2024-2025 Losses | |---|---| | Off-chain attacks (stolen keys, social engineering) | 80.5% of stolen funds | | Compromised accounts | 55.6% of all incidents | | Protocols using multi-sig at time of hack | Only 19% | | Protocols using cold storage at time of hack | Only 2.4% |
The Bybit hack — the single largest crypto theft in history — illustrates the pattern. North Korean operatives from the Lazarus Group did not exploit a smart contract vulnerability. They socially engineered a developer at Safe{Wallet}, compromised his workstation, stole AWS session tokens to bypass MFA, and then manipulated the user interface that Bybit employees used to sign transactions. The on-chain infrastructure was never breached. The people around it were.
Immunefi CEO Mitchell Amador put it bluntly in a January 2026 interview: crypto's worst year for hacks was not a smart contract problem — it was a people problem. AI-enabled impersonation scams showed 1,400% year-over-year growth, and AI-powered scam operations were 450% more profitable than traditional schemes.
The solution to most insider-access exploits is well understood: multi-signature wallets, timelocked administrative functions, and least-privilege access policies. The Infini exploit would have been impossible if the vault's withdrawal function had required signatures from multiple independent parties.
Yet adoption remains alarmingly low. Only 19% of protocols that were hacked in 2024-2025 had implemented multi-signature controls on critical functions. Only 2.4% used cold storage for administrative keys.
The reasons are structural:
Speed vs. Security Trade-off: Multi-sig introduces latency. In fast-moving DeFi markets, protocols compete on execution speed. Adding a 24-hour timelock or requiring 3-of-5 signatures on parameter changes creates friction that teams view as a competitive disadvantage.
Developer Culture: Many DeFi protocols are built by small teams where a single developer may deploy, configure, and administer contracts. The Infini case is typical: the founder trusted a developer with deployment authority and never revoked it. In traditional finance, separation of duties is a regulatory requirement. In DeFi, it is optional.
Cost of Governance Infrastructure: Proper multi-sig setups require operational overhead — key ceremonies, geographic distribution of signers, backup procedures, and ongoing coordination. For early-stage protocols with limited resources, this infrastructure often gets deferred.
False Confidence in Audits: Smart contract audits — even thorough ones — typically focus on code-level vulnerabilities, not on operational access control policies. An audit might verify that a contract's logic is sound while missing the fact that a single externally-owned account holds unrestricted admin privileges. The Infini contracts may have been technically correct; the access control around them was not.
The multisignature wallet market is projected to grow from $1.27 billion to $4.37 billion by 2033, driven largely by institutional demand. But the gap between institutional adoption (where 61% of institutions deploy multi-sig) and protocol-level adoption (where only 19% of hacked protocols had it) represents a massive, exploitable seam.
From an economic-value perspective, access-control failures represent pure value destruction. Unlike market volatility — which redistributes value between participants — exploits extract value from the ecosystem entirely, often routing it through mixers to state-sponsored actors or criminal networks.
With approximately $130-140 billion in total DeFi TVL as of early 2026, the $54 million lost to access-control failures in February alone represents a recurring tax on the ecosystem. Annualized, the $3.4 billion in 2025 theft losses amounts to roughly 2.6% of current TVL — a drag that no traditional financial system would tolerate.
The downstream effects compound. Every major exploit:
The Infini exploit's 70% institutional exposure is particularly damaging. These are the exact capital allocators that DeFi needs to attract for long-term growth. A single rogue developer draining a vault is precisely the scenario that keeps institutional risk committees from approving DeFi allocations.
The Infini exploit was preventable with standard security practices that have existed for years:
Multi-signature administration: If the vault's withdrawal function had required 3-of-5 signatures from independent parties, no single developer could have drained it.
Automated privilege revocation: Developer access should be revoked at deployment through automated mechanisms — not through manual processes dependent on a founder remembering to do it.
Timelocked administrative functions: A 48-hour timelock on any withdrawal exceeding a threshold (e.g., $100,000) would have given the team time to detect and block the attack.
Operational security audits: Beyond code audits, protocols need operational audits that examine who holds which keys, what those keys can do, and whether access follows least-privilege principles.
On-chain monitoring and alerting: Real-time monitoring of administrative function calls — with automatic pause mechanisms — could have frozen the contract before the full $49.5 million was extracted.
None of these are novel. All are standard practice in traditional financial infrastructure. Their absence in a protocol managing $49.5 million in user deposits is a governance failure, not a technology limitation.
The Infini exploit ($49.5M) was caused by a former developer who retained a hidden admin role for 3+ months after deployment — a preventable access-control failure, not a code vulnerability.
February 2026 has already produced $54M+ in losses from access-control and configuration failures across Infini, CrossCurve, and Moonwell, continuing a pattern established throughout 2025.
80.5% of crypto theft in 2024-2025 came from off-chain attack vectors — stolen keys, social engineering, and compromised accounts — not smart contract exploits.
Only 19% of hacked protocols had multi-signature controls, despite multi-sig being the single most effective defense against insider and key-compromise attacks.
DeFi's security crisis is an economic value problem: $3.4 billion in annual theft losses represent a ~2.6% annual tax on total DeFi TVL, eroding institutional confidence and accelerating market consolidation.
The gap between institutional security standards (61% multi-sig adoption) and protocol-level security (19% at time of hack) is the industry's most exploitable seam.
DeFi's security problem has shifted. The era of novel smart contract exploits — reentrancy attacks, flash loan manipulations, price oracle exploits — is giving way to something more mundane and more dangerous: people with too much access making catastrophic mistakes or acting with malicious intent.
The Infini exploit is a case study in what happens when a $49.5 million vault is protected by a single key held by a single person who was never properly offboarded. It is not a new attack. It is the oldest attack in the book — the insider threat — dressed in blockchain terminology.
The industry has the tools to fix this. Multi-signature wallets, timelocked admin functions, automated access revocation, operational security audits, and on-chain monitoring are all mature technologies. What the industry lacks is the discipline to implement them consistently — and the market incentive to do so before, rather than after, the next nine-figure exploit.
Until access control is treated as critical infrastructure rather than operational overhead, DeFi will continue to bleed billions annually to an attack vector that traditional finance solved decades ago. The code is getting better. The people problem is getting worse.