Injective suspended operations for about four hours on Sept. 1 after an attacker exploited a vulnerability in its binary-options system, according to X user Paddy-earthling, as reported by PANews. The attacker used Frontrunner, a deactivated but still-registered oracle (blockchain data feed), whose data sources had already been emptied. By creating 299 markets linked to the oracle, the attacker triggered the platform’s no-price refund mechanism and exploited a flaw that delivered roughly double the intended payout. The stolen funds were converted from USDC into about 1,980 ETH, worth approximately $4.9 million, and are currently held in an Ethereum wallet that has never sent a transaction. Paddy-earthling also said Injective’s official X account continued posting marketing content after the attack without mentioning that the chain had been suspended.