Cryptelio

Injective Blockchain Halts for Four Hours Amid $4.9 Million Exploit Response

Cryptelio Editorial Published 2 Sep 2026 · 12:45 UTC
Injective Blockchain Halts for Four Hours Amid $4.9 Million Exploit Response

Injective, a layer-1 blockchain network, experienced a significant disruption as it halted block production for nearly four hours in response to a security exploit. The incident, which occurred on August 31, was characterized by the Injective Foundation as an upgrade rather than a halt, despite the emergency measures taken to contain the exploit.

On September 1, the foundation stated that its consensus mechanism, native INJ token, and staked assets were not compromised, indicating that the attack primarily affected a small number of ecosystem applications utilizing binary-options markets. However, on-chain researcher Paddy raised concerns about this characterization, suggesting that the exploit was more widespread and involved vulnerabilities in Injective’s core modules.

The blockchain's last recorded block before the interruption was at 16:09:59 UTC on August 31, with block production ceasing for approximately four hours. During this time, some validators were temporarily jailed for missing the upgrade window, and major exchanges like Coinbase and Coins.ph restricted transfers.

Paddy noted that the exploit utilized messages from Injective’s native exchange and insurance modules, indicating that the vulnerability was not limited to application code. The emergency release, which aimed to patch the core code, included measures such as adding an insurance-fund denomination check and disabling binary-options settlements on the mainnet.

While researchers estimated that around $4.9 million was bridged to Ethereum during the exploit, it remains unclear how much was ultimately lost or how the losses were allocated among affected parties. Injective has not yet provided a full technical postmortem of the incident, but it has assured users that their funds were safe.

In a statement, Injective CEO Eric Chen emphasized that users were not affected and praised the team for containing the incident before it could cause further damage. Despite this assurance, the incident highlights the ongoing vulnerabilities within blockchain ecosystems, even among platforms that have undergone security audits.

FAQ

What caused the Injective blockchain to halt for four hours?

The Injective blockchain halted for nearly four hours in response to a security exploit that affected a small number of ecosystem applications utilizing binary-options markets.

Was the Injective consensus mechanism or native INJ token compromised during the exploit?

No, the Injective Foundation stated that its consensus mechanism, native INJ token, and staked assets were not compromised during the exploit.

What measures were taken to address the security exploit?

An emergency release was implemented to patch the core code, which included adding an insurance-fund denomination check and disabling binary-options settlements on the mainnet.

How much money was estimated to be bridged to Ethereum during the exploit?

Researchers estimated that around $4.9 million was bridged to Ethereum during the exploit, although it is unclear how much was ultimately lost.

What assurances did Injective provide to its users following the incident?

Injective assured users that their funds were safe and emphasized that users were not affected by the exploit, with CEO Eric Chen praising the team for containing the incident.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha