News Report Technology
September 01, 2026

Injective Exploited For $4.9M Via Market ID Collision In Binary Options Settlement Logic

Injective Exploited For $4.9M Via Market ID Collision In Binary Options Settlement Logic

Injective, a Layer 1 blockchain protocol specializing in decentralized finance, was targeted in an exploit on August 31 that drained approximately $4.9 million through a critical vulnerability in its binary options settlement system. 

The attacker systematically abused a permissionless market-creation mechanism to launch 299 instant binary options markets over a 19-hour period, each administered through a self-controlled oracle deliberately configured to never provide prices. Oracle symbols were explicitly constructed to trigger the no-price refund path, with expiration and settlement timestamps set mere seconds apart.

On-chain analysis reveals the exploit relied on self-matched trades across the attacker’s own subaccounts. The actor deposited collateral, assumed both long and short positions at manipulated prices, and exploited the refund mechanism to extract roughly twice the deposited amount per cycle. 

In one documented sequence, approximately 105,000 USDC generated withdrawals exceeding 204,000 USDC. The proceeds were subsequently bridged to Ethereum via CCTP, swapped for ETH on Uniswap, and consolidated in address 0x5a18…69ea, where roughly 1,980 ETH—approximately $4.88 million—remained unmoved at press time.

The Injective chain halted for approximately three hours and 42 minutes, from block 181,027,006 at 16:10 UTC to block 181,027,007 at 19:52 UTC. Unlike Cronos, which rolled back transactions following a recent incident, Injective advanced by exactly one block across the seam, preserving all executed trades. The final exploit attempt failed only because its settlement timestamp expired amid severely slowed block production, which had dropped to roughly 38-minute intervals immediately before validators intervened.

Technical Flaw and Transparency Criticism

The root cause traces to a market identifier collision in Injective’s core logic. The protocol generates market_id by concatenating oracleType, ticker, quoteDenom, oracleSymbol, and oracleProvider without separators or length prefixes. This hashing scheme allowed the attacker to create an INJ-denominated insurance fund that collided with the identifier of a USDC-denominated binary options market. 

When settlement entered the no-price refund path, the system attempted to cover the manufactured USDC deficit using the raw integer balance of the attached INJ fund. Because the code treated minimal INJ balances as sufficient coverage for the dollar-denominated shortfall, it bypassed the required haircut among remaining positions and permitted full withdrawals of artificially inflated balances.

The incident has renewed scrutiny of Injective’s decision to remove its core chain repositories from GitHub, a move previously justified as reducing attack surface. 

Critics contend the exploit demonstrates the fundamental limits of security through obscurity: the attacker relied solely on public SDK documentation, legacy compiled binaries up to version 1.17.2, and the live Frontrunner testnet to empirically reverse-engineer the vulnerability. Meanwhile, independent auditors and whitehat researchers were denied the source-level access necessary to identify the flaw proactively.

Communication failures compounded the technical breach. Throughout the halt, Injective’s official social media channels published marketing content promoting new products, without acknowledging the incident or reassuring users. This approach contrasted sharply with protocols like MANTRA and Cronos, which publicly disclosed recent outages. 

An on-chain message offering a bounty was sent to the attacker from an unverified smart wallet, though Injective has not confirmed official involvement, and the sender’s identity remains ambiguous. At the time of writing, the protocol had issued no public statement regarding the exploit, its impact on users, or planned remediation measures.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Hot Stories
Join Our Newsletter.
Latest News

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More

How Minmax Is Building The Professional AI Trading Terminal Prediction Markets Still Lack In 2026

Minmax processed roughly $100,000 in volume in the first three days of June, most of it through ...

Know More
Read More
Read more
Telegram Begins Phased Rollout Of Native Non-Custodial Gram Wallet With Validator-Approved Smart Contracts
News Report Technology
Telegram Begins Phased Rollout Of Native Non-Custodial Gram Wallet With Validator-Approved Smart Contracts
September 1, 2026
Gate Update: Stablecoin Yield, Precious Metals Dominance, And AI Cashback Lead A Busy Week Of Launches
Digest News Report Technology
Gate Update: Stablecoin Yield, Precious Metals Dominance, And AI Cashback Lead A Busy Week Of Launches
August 31, 2026
HSC Conference Ho Chi Minh: Stablecoins Won The Payments War—Here Is What The Industry Must Solve Next
Hack Seasons Interview Business Lifestyle Markets
HSC Conference Ho Chi Minh: Stablecoins Won The Payments War—Here Is What The Industry Must Solve Next
August 31, 2026
Top 10 White Label Crypto Wallet Providers For Fintech Startups In 2026
Top Lists Business Technology
Top 10 White Label Crypto Wallet Providers For Fintech Startups In 2026
August 31, 2026