Injective was reportedly paused for about four hours after an attacker exploited a vulnerability tied to its binary options markets, resulting in roughly $4.9 million in losses. The exploit allegedly used a deactivated but still registered oracle called Frontrunner, whose data source had long been emptied.
The attacker reportedly created 299 markets linked to the oracle, triggering a no-price refund mechanism when prices could not be fetched. A flaw in that refund process allegedly enabled payouts of roughly double the expected amount. The stolen USDC was then swapped into about 1,980 ETH, valued near $4.9 million, and moved to an Ethereum wallet that has not sent any transactions.
The report said the protocol-layer shortfall has already been covered, but no governance vote or public explanation has been provided, leaving the fix unverified. The attacker has consolidated the funds into a single wallet and has not moved them, reportedly while weighing a white-hat settlement proposal.
Injective Faces $4.9 Million Exploit Linked to Binary Options Oracle Flaw
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
