Injective allegedly halts for four hours after $4.9 million binary-options exploit

  • Injective apparently paused after an attacker exploited a binary-options vulnerability.
  • The attacker created 299 markets and obtained about $4.9 million in assets.
  • The funds are held in an Ethereum wallet that has never sent a transaction.

Injective appears to have paused for about four hours after an attacker exploited a vulnerability in its binary-options mechanism, according to monitoring by Paddy-earthling cited by Odaily. The attacker used a disabled but still-registered oracle (a blockchain data provider) whose data sources had been emptied, created 299 markets linked to it and triggered the platform's no-price refund process. Exploiting that mechanism produced a payout of about twice the expected amount, with the attacker then exchanging USDC for approximately 1,980 ETH worth about $4.9 million. The assets are currently held in an Ethereum wallet that has never sent a transaction. Paddy-earthling also said Injective's official account continued publishing marketing content after the incident without mentioning that the chain had been paused.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.