On August 31, 2026, layer-1 blockchain Injective was exploited when an attacker abused its permissionless binary-options market creation and a flaw in how the protocol generates market identifiers, draining approximately $4.9 million. The chain halted for roughly three hours and 42 minutes to stop the attack; the drained funds were bridged to Ethereum, where about 1,980 ETH (~$4.88 million) was consolidated in a single address.
What happened
Injective built each market's identifier by concatenating oracle parameters — type, ticker, quote denomination, symbol, and provider — without separators or length prefixes. That let the attacker engineer a collision between an INJ-denominated insurance fund and a USDC-denominated binary-options market. Over about 19 hours the attacker created 299 instant binary-options markets, each wired to a self-controlled oracle configured never to supply a price and with expiration and settlement timestamps set seconds apart. Using self-matched trades across multiple subaccounts, the attacker triggered the "no-price refund" path, which attempted to cover USDC shortfalls using INJ balances and treated minimal INJ holdings as sufficient coverage for dollar-denominated deficits. In one documented cycle, roughly 105,000 USDC in deposits produced withdrawals exceeding 204,000 USDC — about doubling the stake each iteration.
Aftermath
Injective's validators halted the chain from block 181,027,006 (16:10 UTC) to block 181,027,007 (19:52 UTC), advancing exactly one block across the seam so that executed trades were preserved rather than rolled back. Injective said consensus, native INJ, and staked funds were never compromised and framed the pause as an upgrade. As of reporting the protocol had issued no remediation statement and the roughly 1,980 ETH remained unmoved in the attacker's address, so the status here is stolen. Commentators noted the attacker reverse-engineered the bug from public SDK docs, legacy compiled binaries, and the live testnet despite Injective having removed core repositories from GitHub.
Why it matters
Like the Maya Protocol exploit earlier in August, this attack lived not in a single lending contract but in an app-specific chain's own settlement and accounting logic, where one flawed assumption — here, that a market identifier is unique — cascades into fabricated value. Permissionless market creation combined with a refund path that conflated INJ and USDC accounting turned a naming shortcut into a money printer. The episode is a reminder that identifier construction, permissionless listing, and cross-denomination settlement are as security-critical as any swap function, and that "security through obscurity" — hiding source code — does little against a determined attacker.
Sources & on-chain evidence
- [01]mpost.iohttps://mpost.io/injective-exploited-for-4-9m-via-market-id-collision-in-binary-options-settlement-logic/
- [02]coinpaprika.comhttps://coinpaprika.com/news/injective-froze-four-hours-stop-49m-exploit/
- [03]coinmarketcap.comhttps://coinmarketcap.com/top-stories/6a973de4f2b8186f115c0ca0/