Injective Stopped Producing Blocks for Four Hours to Contain a $4.9 Million Exploit, Then Called It an Upgrade
The Injective exploit on 31 August drained about $4.9 million and stopped block production for three hours and forty-two minutes, which the foundation described as an upgrade, not a halt.
On this page
- What the attacker did
- The halt Injective says was not a halt
- Why this keeps happening
- The trade-off nobody wants to state plainly
- What the announcement could have said
- What to watch
- The pattern across the year
- The disclosure standard worth asking for
On 31 August an attacker drained approximately $4.9 million from Injective and bridged it to Ethereum. Block production stopped for three hours and forty-two minutes. Block 181027005 appeared at 16:09:59 UTC before the gap, with one earlier block taking roughly 37 minutes to process.
The Injective Foundation said the blockchain was "upgraded, not halted." A security researcher who examined the emergency patch says that characterisation does not survive contact with the code.
The dispute is more interesting than the loss.
What the attacker did
The exploit used a market ID collision in binary options settlement logic. In plain terms: the settlement code could be made to treat one market's identifier as another's, allowing the attacker to extract value the contract believed it was paying out legitimately.
The critical detail is where the flaw lived. Injective initially described the impact as confined to ecosystem applications built on the chain rather than the chain itself. Researcher Earthling Paddy examined the emergency patch — version v1.20.3-safeharbor.1 — and found it modified core protocol code: adding an insurance-fund denomination check and disabling binary options settlement outright.
Patches to the native exchange and insurance modules are not application-level fixes. They are chain-level fixes, which places the vulnerability in the protocol instead of in something built on top of it.
The halt Injective says was not a halt
CEO Eric Chen stated: "Injective users aren't affected and we've been helping the team on recovery." The foundation maintained that consensus, native INJ and staked assets were never compromised.
Both claims can be true while the chain still stopped producing blocks for nearly four hours. Those are different properties. A chain can preserve the integrity of its ledger — nobody's balance was falsified — while failing to preserve liveness, its ability to keep processing transactions.
Liveness failure is not a minor property. During that window, no user could move funds, no liquidation could execute, no oracle update could land. Some validators were temporarily jailed for missing the upgrade window. Coinbase and Coins.ph restricted transfers.
Calling that an upgrade is a communications decision. It is not a technical description.
Why this keeps happening
Injective was not alone. The same week produced a cluster of comparable incidents on alternative chains.
More Markets on Flow lost 15.5 million WFLOW, roughly $9.3 million.
Zilliqa executed an emergency hard fork to address a signature padding bug.
Full Sail on Sui saw $91,000 stolen, triggering roughly $455,000 of liquidations across 45 accounts.
Ontology also halted its mainnet.
Four chains, one week, four different failure modes: a settlement logic flaw, an application exploit, a cryptographic implementation bug, and a liquidation cascade.
The common factor is not incompetence. It is that a chain with a small, coordinated validator set can be stopped and patched within hours — and once that capability exists, it gets used. The alternative is watching the loss continue.
The trade-off nobody wants to state plainly
This is the same question raised by Cronos halting to contain the $120.4 million Tectonic exploit in August. It has an uncomfortable answer.
A chain that can be halted is not credibly neutral. If a small group can agree to stop the network, they can be compelled to stop it — by a regulator, a court, or their own commercial interest. The property that saved $4.9 million here is the same property that makes a chain a permissioned system with extra steps.
A chain that cannot be halted keeps producing blocks while the attacker drains it. Ethereum and Bitcoin sit in this category by design. They have never been stopped, and the cost of that guarantee is that losses run to completion.
Neither answer is wrong. What is wrong is claiming both — marketing decentralisation while operating a system with an off switch, and then describing use of the off switch as routine maintenance.
What the announcement could have said
There is a straightforward version of this announcement that costs nothing and preserves credibility.
State that a flaw in the settlement module allowed an attacker to extract $4.9 million. State that validators coordinated to pause block production for three hours and forty-two minutes while a patch was prepared and deployed. State that ledger integrity was never at risk and no user balances were falsified. State that the trade-off was chosen deliberately: liveness was sacrificed to contain the loss.
Every one of those statements is true, and together they describe a competent incident response. The reason to say "upgraded, not halted" instead is that it avoids the word "halted" — and the cost is that the first researcher to read the diff finds the discrepancy and the story becomes the framing, not the fix.
What to watch
Whether the funds are recovered. The $4.9 million reached Ethereum. Tracing and exchange cooperation determine what comes back.
Whether binary options settlement is re-enabled. The patch disabled it. Restoring it requires a fix rather than a switch.
Post-mortem quality. A detailed technical post-mortem naming the flaw and the timeline is the standard. Anything less confirms the communications-first read.
Whether validator sets get formal halt procedures. Several chains now have de facto emergency powers with no documented process governing them. Writing that process down would be an improvement over exercising it ad hoc.
The pattern across the year
August produced $215 million in confirmed losses across the sector, with price manipulation accounting for $131.6 million of it — including the $120.4 million Tectonic exploit, which Cronos also halted to contain. September has opened with a settlement-logic flaw, an application exploit, a cryptographic bug and a liquidation cascade across four different chains.
The through-line is not that code quality has fallen. Audits, formal verification and bug bounties have made contract code materially harder to break than it was in 2021, and code vulnerabilities ranked fourth by loss value in August.
What keeps failing is the layer above the code: the assumptions a protocol makes about market identifiers, oracle prices, collateral liquidity and settlement uniqueness. Those are design decisions instead of implementation bugs, and no audit catches a design that behaves exactly as written while producing an outcome nobody intended.
Injective's market ID collision is a clean example. The settlement logic did what it was told. It was told the wrong thing.
The disclosure standard worth asking for
Three items make an incident report credible: the specific flaw, named and located in the code; the exact timeline, including any period the chain was not producing blocks; and the trade-off the team chose, stated as a choice, not described as maintenance.
Injective's response supplied the third only after a researcher read the patch. That sequencing is the part that costs trust, and it is entirely avoidable — the underlying incident response was competent.
About this report. Exploit mechanism, amount, block numbers, halt duration and the patch version are from CryptoSlate's reporting and the analysis by researcher Earthling Paddy. Injective's statements are as quoted in that coverage and in The Crypto Times. Other chain incidents are from the Bitcoin News Digest of 6 September 2026. Recovery figures may change.
Not investment or security advice. Incident details are reported as published and remain subject to revision.
Related reading
- Liquid Hack: 85% of Bitcoin Returned, $47M Kept as Bounty
- Elements Range Proof Bug: How 4,000 Fake L-BTC Was Minted
- White Hat Bounty Norms: Who Decides What a Hacker Keeps?
- DeFi Market Cap $78bn Against $1.6bn in 2026 Hack Losses
Sources
- Injective disputes four-hour halt claim after $4.9 million exploit — CryptoSlate
- Injective Exploited For $4.9M Via Market ID Collision In Binary Options Settlement Logic — Metaverse Post
- Injective Confirms Secure Network Upgrade After App Exploit — The Crypto Times
- Bitcoin News Digest, September 6, 2026 — Mike Richardson
Read next
- The Liquid Attackers Gave Back 3,400 Bitcoin and Kept $47 Million. Nobody Agreed to That. Liquid Network attackers returned 3,400 BTC of the roughly 4,000 taken, keeping about $47 million they descri…
- A Bitcoin Sidechain Just Lost 95% of Its Reserves. The Federation Multisig Held. The Liquid Network hack drained about 3,996 BTC worth $320m on 6 September, roughly 95% of reserves, through …
- $215 Million Gone in August, and One Attack Accounted for More Than Half of It CertiK counted $215m in confirmed crypto losses in August 2026, with $144.6m from DeFi. The Tectonic exploit …