Injective Network Hit by $4.9M Exploit and Outage
Injective network suffers a $4.88 million exploit via a binary options vulnerability, leading to a nearly 4-hour mainnet outage on August 31.
According to Injective halted for ~4 hours today after a binary-options exploit drained multiple assets. In that window, the official @injective account posted twice — both marketing. "ICYMI our AI Agent SDK is live." "Bridge your ETH to Injective." Zero mention of the halt. No "funds are…
The attacker created 299 short-lived markets using an oracle configured to fail at providing the necessary price during settlement. When a valid price is missing, the protocol defaults to a refund mechanism. This fallback procedure was exploited to extract more collateral than was originally deposited.
Analysis indicates the attacker traded between their own sub-accounts, simultaneously holding long and short positions. Once the refund mechanism was triggered, they were able to withdraw approximately double the initial capital across separate cycles. In one documented instance, a deposit of roughly 105,000 USDC allowed for withdrawals exceeding 204,000 USDC.
The Issue May Run Deeper Than the Oracle
Initial reports linked the attack to an inactive but still registered oracle. However, specific details point toward a potential flaw in how Injective generates market identifiers. Several parameters are combined to create a “market_id,” which reportedly allowed for an ID collision between different markets and denominations.
When the refund procedure was activated, the system may have treated minimal balances as sufficient to cover significantly larger liabilities. This suggests the missing oracle price was likely just the trigger for a deeper vulnerability in the settlement logic rather than the sole cause of the exploit.
Injective Halts Block Production for Nearly 4 Hours
The incident coincided with a nearly four-hour outage of the mainnet. Block production stopped at block 181,027,006 around 16:10 UTC on August 31 and resumed with block 181,027,007 at approximately 19:52 UTC.
Critically, no rollback of confirmed transactions occurred during the recovery. The network resumed from the next block after an emergency patch was applied. Shortly before the full shutdown, block times increased significantly; a final attempt to exploit the vulnerability failed because the settlement time expired during the delay.
Nearly $4.9 Million Reaches Ethereum
Funds from the suspected exploit were moved from Injective to Ethereum via Circle CCTP. A portion of these assets was subsequently swapped through Uniswap and consolidated into ETH. On-chain data shows approximately 1,979.8 ETH, valued at roughly $4.88 million, collected in a single address.
.@injective halted for 3h 42m on 31 August. Here is what the chain records, pulled from archive nodes.
— Rarma (@Rarma_) September 1, 2026
The halt: last block 181,027,006 at 16:10:02 UTC, next block 181,027,007 at 19:52:14. Height advanced by one across the seam, so nothing was rolled back — the opposite of what… pic.twitter.com/40mZ4iIsSu
The lack of an official technical report from Injective remains a key missing piece. While independent analyses describe the mechanism, fund movements, and blockchain downtime, the final loss amount, the exact nature of the vulnerability, and the scope of the fix can only be confirmed following a public disclosure from the team.

Fill in necessary fields and publish