Injective was reportedly paused for about four hours on Sept. 1 after a binary options exploit led to the loss of about $4.9 million, according to PANews, citing X user Paddy-earthling. The account said the attacker abused Frontrunner, a deprecated oracle that remained registered even though its data source had long been cleared. By creating 299 markets tied to that oracle, the attacker allegedly forced a "no price refund" condition and then exploited that refund logic to receive roughly 2x payouts.
The stolen USDC was then swapped into about 1,980 ETH, valued at around $4.9 million in the report, and the funds are now sitting in an Ethereum wallet that has never sent any transaction. Paddy-earthling also said Injective’s official X account continued posting marketing content after the incident without mentioning the chain halt. The post added that Injective made its core chain code private, while the attacker was still able to identify the issue through the public SDK. According to the same disclosure, the protocol-level shortfall has already been covered, but the remediation process involved no governance vote and no public explanation, leaving the fix unverifiable from the outside. The author also disclosed holding a long INJ position.
Injective was reportedly halted for about four hours on Sept. 1 after a binary options exploit drained roughly $4.9 million, according to PANews, which cited X user Paddy-earthling.
Exploit allegedly used a deprecated oracle
Paddy-earthling said the attacker abused Frontrunner, an oracle that had been deprecated but was still registered. Its data source had already been cleared, according to the post. The attacker then created 299 markets pointing to that oracle. Because no price could be fetched, the setup triggered a "no price refund" mechanism, which the attacker allegedly used to obtain roughly 2x compensation.
After that, the attacker swapped USDC into about 1,980 ETH, valued at around $4.9 million in the report. The funds are currently held in an Ethereum wallet that has never sent any transaction.
Questions raised over communications and remediation
Paddy-earthling also said Injective’s official X account kept posting marketing material after the attack and did not mention that the chain had been paused. The post added that Injective had made its core chain code private, but the attacker was still able to find the flaw through the public SDK. In Paddy-earthling’s view, that move excluded white-hat researchers and auditors instead.
According to the disclosure, the funding gap has already been covered at the protocol level. Even so, there was no governance vote and no public explanation for the repair process, leaving outsiders unable to verify it. Paddy-earthling said the attacker has consolidated all of the funds into one wallet and has not moved them, suggesting the party may still be weighing a white-hat settlement proposal.
The author also disclosed holding a long position in INJ.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.