Injective Network Hit by $4.9M Exploit and Outage

We may earn commissions from affiliate links or include sponsored content, clearly labeled as such. These partnerships do not influence our editorial independence or the accuracy of our reporting. By continuing to use the site you agree to our terms and conditions and privacy policy.

Article Details

Injective network suffers a $4.88 million exploit via a binary options vulnerability, leading to a nearly 4-hour mainnet outage on August 31.

According to

, the attack targeted Injective’s permissionless system designed for creating and settling binary options markets.

The attacker created 299 short-lived markets using an oracle configured to fail at providing the necessary price during settlement. When a valid price is missing, the protocol defaults to a refund mechanism. This fallback procedure was exploited to extract more collateral than was originally deposited.

Analysis indicates the attacker traded between their own sub-accounts, simultaneously holding long and short positions. Once the refund mechanism was triggered, they were able to withdraw approximately double the initial capital across separate cycles. In one documented instance, a deposit of roughly 105,000 USDC allowed for withdrawals exceeding 204,000 USDC.

The Issue May Run Deeper Than the Oracle

Initial reports linked the attack to an inactive but still registered oracle. However, specific details point toward a potential flaw in how Injective generates market identifiers. Several parameters are combined to create a “market_id,” which reportedly allowed for an ID collision between different markets and denominations.

When the refund procedure was activated, the system may have treated minimal balances as sufficient to cover significantly larger liabilities. This suggests the missing oracle price was likely just the trigger for a deeper vulnerability in the settlement logic rather than the sole cause of the exploit.

Injective Halts Block Production for Nearly 4 Hours

The incident coincided with a nearly four-hour outage of the mainnet. Block production stopped at block 181,027,006 around 16:10 UTC on August 31 and resumed with block 181,027,007 at approximately 19:52 UTC.

Critically, no rollback of confirmed transactions occurred during the recovery. The network resumed from the next block after an emergency patch was applied. Shortly before the full shutdown, block times increased significantly; a final attempt to exploit the vulnerability failed because the settlement time expired during the delay.

Nearly $4.9 Million Reaches Ethereum

Funds from the suspected exploit were moved from Injective to Ethereum via Circle CCTP. A portion of these assets was subsequently swapped through Uniswap and consolidated into ETH. On-chain data shows approximately 1,979.8 ETH, valued at roughly $4.88 million, collected in a single address.

The lack of an official technical report from Injective remains a key missing piece. While independent analyses describe the mechanism, fund movements, and blockchain downtime, the final loss amount, the exact nature of the vulnerability, and the scope of the fix can only be confirmed following a public disclosure from the team.

Leave Reaction
Share Article
Nikolay is a cryptocurrency analyst and market writer with years of experience tracking digital asset trends and emerging blockchain technologies. A long-time crypto enthusiast, he actively trades across major exchanges and specializes in identifying early-stage projects and meme tokens. His analysis combines technical insight with a strategic, long-term investment perspective.
comment-icon Commentaries
Add your comment

Fill in necessary fields and publish