Injective's block production stalled for roughly four hours on Aug. 31 as validators deployed an emergency patch following an exploit that drained approximately $4.9 million from native protocol modules.
"The attack used messages from Injective's native exchange and insurance modules," Earthling Paddy, an on-chain researcher, said, crediting the foundation for containing the exploit while challenging its description of the incident as isolated to ecosystem applications.
The ledger shows block 181027005 at 16:09:59 UTC on Aug. 31 before production stopped for roughly four hours. Paddy said one earlier block alone took about 37 minutes, while infrastructure provider QuickNode also reported a stalled block height. The emergency v1.20.3-safeharbor.1 release added an insurance-fund denomination check and disabled binary-options settlement on mainnet. Some validators were temporarily jailed after missing the required upgrade window, and exchanges including Coinbase and Coins.ph restricted transfers.
INJ traded around $4.80 as of press time, down roughly 3 percent over 24 hours. The foundation said consensus, native INJ, and staked assets were never compromised, describing the attack as affecting a small number of ecosystem applications using binary-options markets.
Injective has not published a full technical postmortem or disclosed how much was ultimately drained, which party absorbed any shortfall, or whether an ecosystem pool that now appears replenished was restored by the foundation, developers, or another participant. Researchers estimate about $4.9 million was bridged to Ethereum during the exploit, with roughly that amount still held in the attacker-linked wallet.
CEO Eric Chen said Injective users were not affected and that the team was helping with recovery. "Always sad to see exploits happening in the ecosystem but we're glad that the incident was contained before further harm was done," he said on X.
The incident leaves two findings intact: Injective's consensus and staked INJ were not compromised, while its emergency response still coincided with a multi-hour interruption in block production and required a core-code patch. The unresolved loss allocation and the absence of a full postmortem leave open questions about whether the attack vector is fully closed and how the foundation will restore confidence in its binary-options infrastructure.
The exploit lands during a rough stretch for on-chain security. Crypto hacks rose 67 percent in August to about $136 million in losses, according to PeckShield, with Injective among the ten largest named incidents alongside MANTRA and BounceBit. The same day also saw a separate exploit of the Tectonic lending protocol on Cronos.
This article is for informational purposes only and does not constitute investment advice.