Injective A blockchain vulnerability led to the theft of approximately $4.8 million, which has now been fixed
2026-09-02 20:00:42
According to CoinMeta, the Injective platform encountered a binary options settlement vulnerability on September 1st, resulting in the theft of approximately $4.8 million. The attackers exploited this vulnerability to transfer funds to Ethereum and exchanged them for ETH. This attack utilized a combination of three vulnerabilities, which led to the suspension of the chain, and a patch has since been released. The vulnerabilities included: 1. Unlimited market ID string concatenation causing ID conflicts; 2. Self-trading that fabricated false settlement deficits; 3. Mismatch in decimal points leading to the rounding of remaining deficits to zero. Following the attack, Injective suspended the chain and deployed a patch, strictly enforcing the matching of the deposit currency of the insurance fund with the market quoted currency, effectively sealing off the vulnerability.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.