Injective appears to have paused for about four hours after an attacker exploited a vulnerability in its binary-options mechanism, according to monitoring by Paddy-earthling cited by Odaily. The attacker used a disabled but still-registered oracle (a blockchain data provider) whose data sources had been emptied, created 299 markets linked to it and triggered the platform's no-price refund process. Exploiting that mechanism produced a payout of about twice the expected amount, with the attacker then exchanging USDC for approximately 1,980 ETH worth about $4.9 million. The assets are currently held in an Ethereum wallet that has never sent a transaction. Paddy-earthling also said Injective's official account continued publishing marketing content after the incident without mentioning that the chain had been paused.