Injective Pauses Operations for 4 Hours Following $4.9 Million Binary Options Exploit



Injective, a Layer 1 blockchain protocol focused on decentralized finance, was forced to pause operations for approximately four hours on September 1 after an attacker exploited a vulnerability in its binary options settlement system, stealing approximately $4.9 million. The attacker exploited a decommissioned but still registered oracle (Frontrunner) whose data sources had been cleared, creating 299 markets pointing to that oracle to trigger a "no-price refund" mechanism that paid out 2x. The attacker then bridged approximately $4.9 million across to Ethereum, where the funds remained at the time of reporting. This incident represents a sophisticated attack targeting the protocol's settlement logic, and Injective's temporary pause allowed the team to investigate and address the vulnerability. The exploit highlights the ongoing security challenges facing DeFi protocols, particularly those involving complex financial instruments like binary options.
#GateEventContractTradeSharingChallenge
INJ-2.95%
ETH-2.42%
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
31 views
  • Reward
  • 2
  • 2
  • Share
Comment
Add a comment
Add a comment
MACDTraveller
· an hour ago
After a 4-hour pause, $4.9 million was swapped. That’s fast for a stop-loss, but not fully clearing the deprecated oracle was a rookie mistake.
View OriginalReply0
IchimokuPractitioner
· an hour ago
Frontrunner oracles were all decommissioned, yet registration was left in place; the attacker exploited the loophole precisely. Cleaning up DeFi’s legacy systems is truly a major headache.
View OriginalReply0
  • Pinned