CoinTrust

Injective Faces Four-Hour Block Halt After Protocol Exploit

injective

Injective, a layer-1 blockchain network, experienced an approximately four-hour interruption in block production on Aug. 31 while validators and ecosystem infrastructure responded to an exploit linked to core protocol modules.

The Injective Foundation said on Sept. 1 that the network had undergone an emergency upgrade rather than being halted and maintained that its consensus mechanism, native INJ tokens and staked assets had not been compromised. The foundation characterized the incident as an attack involving a limited number of ecosystem applications operating binary-options markets.

On-chain researcher Earthling Paddy disputed parts of that description while acknowledging that Injective had moved quickly to contain the exploit and protect staked funds.

Blockchain records showed that block 181027005 was produced at 16:09:59 UTC on Aug. 31, after which block production stopped for roughly four hours. Paddy also reported that one earlier block had taken about 37 minutes to complete. Infrastructure provider QuickNode separately identified a stalled block height during the incident, reinforcing evidence of a significant disruption to normal network operations.

Injective attributed the prolonged interruption to the accelerated upgrade process. Validators and supporting infrastructure had to migrate to the emergency software release, with some validators temporarily jailed after failing to complete the upgrade within the required period. Several cryptocurrency exchanges, including Coinbase and Coins.ph, also temporarily restricted transfers involving Injective.

Core Protocol Modules at Center of Exploit

Paddy challenged the foundation’s description that the vulnerability was confined to ecosystem applications. According to his analysis, the attack involved messages associated with Injective’s native exchange and insurance modules.

The emergency release, identified as v1.20.3-safeharbor.1, introduced changes to the blockchain’s core code. Among them was an insurance-fund denomination check, while binary-options settlement was disabled on mainnet as part of the response.

The changes indicate that the vulnerable logic was located within a protocol module used by applications, rather than being limited exclusively to independent application code.

Injective has not yet released a complete technical postmortem detailing the exploit, its precise execution path or the full financial impact. The foundation said the attack vector had been contained and patched and that it was implementing stronger system invariants, real-time monitoring and additional security measures to reduce the likelihood of similar incidents.


Nearly $5 Million Bridged During Incident

Researchers estimated that approximately $4.9 million was bridged to Ethereum during the exploit. Paddy indicated that roughly that amount remained in a wallet associated with the attacker and had not subsequently moved.

However, the final financial loss remains uncertain. Injective has not publicly specified how much cryptocurrency was ultimately drained, who absorbed any resulting shortfall, or how an ecosystem pool that later appeared replenished was restored. It also remains unclear whether the replenishment came from the foundation, developers, or another participant in the ecosystem.

The foundation has maintained that users were not affected by the incident. Injective CEO Eric Chen also said the organization was assisting with recovery and expressed relief that the exploit had been contained before causing additional damage.

The incident leaves two distinct conclusions. Injective’s consensus system and staked INJ remained secure, while the network nevertheless experienced a substantial interruption in block

For developers and users, the episode highlights both the resilience of Injective’s validator and staking infrastructure and the risks associated with protocol modules that support ecosystem applications.

The absence of a full technical postmortem means several questions about the exploit’s mechanics, financial losses, and recovery process remain unresolved. Until further details are released, the incident represents a significant test of Injective’s emergency-response procedures and the security boundaries between its core protocol and applications built on the network.

Exit mobile version