Injective Suspends Operations for About 4 Hours Due to Binary Options Vulnerability, $4.9 Million Stolen

By: x.com|2026/09/01 00:54:00

Injective suspended operations for about 4 hours due to a vulnerability in its binary options. Attackers exploited a deprecated but still registered oracle to steal approximately $4.9 million. The data source for this oracle has been cleared, and the attackers created 299 markets pointing to this oracle. Unable to obtain prices, they triggered the 'no price refund' mechanism, exploiting a loophole to receive about double the compensation. They then exchanged USDC for approximately 1,980 ETH, which was stored in an Ethereum wallet that had never conducted any transactions. After the attack, Injective's official X account continued to post marketing content without mentioning the chain's suspension. Injective has made its core chain code private, but the attackers discovered the vulnerability through the public SDK, excluding white hats and auditors. The funding gap has been filled at the protocol level, but the repair process lacked governance voting and public disclosure, making verification impossible. The attackers currently have consolidated all funds into one wallet without moving them, seemingly weighing white hat settlement proposals.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

Injective Announces Introduction of Native Privacy Features

Injective (INJ) has announced the upcoming introduction of native privacy features at the protocol level, aiming to protect information and ensure verifiability when handling institutional assets.

Pineapple Financial Migrates Over $10 Billion in Loans to Injective, Completes Over $1 Billion Record on Chain

Global Lineup Expands for 'GWDC 2026 KOREA' Featuring Koo Yun-cheol, Min Byung-deok, Justin Sun, Bithumb, and Naver

The global Web3 developer conference GWDC 2026 KOREA, co-hosted by TokenPost, will take place in Seoul this September, featuring a large lineup of speakers from various sectors including policy, finance, and big tech.

Injective Experiences $4.9 Million Attack, No New Blocks Produced for 4 Hours

Block production halted for nearly 4 hours after block 181027005 recorded at UTC 16:09:59 on August 31 • Emergency version v1.20.3-safeharbor.1 added checks for the insurance fund and disabled binary options liquidation • Researchers estimate approximately $4.9 million was transferred to Ethereum, w...

Polygon Labs issues urgent client upgrade notice following Austin and Kyoto hardforks

The Polygon upgrades closed separate block-stall, peer-crash, and validator-work risks, leaving nodes on older binaries outside canonical consensus.

Injective Expands Support for Over 60 Chains in Partnership with LI.FI

Injective (INJ) has partnered with cross-chain routing provider LI.FI to broaden the bridge, swap, and deposit pathways between Injective and USD Coin (USDC). This integration adds another bridge...
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com