Risk Radar

Risk Detail / high

Injective Binary-Options Exploit: What Is Confirmed and Why the Network-Halt Claim Is Disputed

Injective says a binary-options app exploit triggered an accelerated upgrade while core chain/user funds remained secure; external evidence points to a material block interruption and an estimated $4.9M loss.

September 2, 2026Last updated 10:30 UTC2 min read

What happened

Injective confirmed that a limited number of ecosystem applications operating binary-options markets were exploited. Contributors coordinated an accelerated network upgrade and the project says the relevant attack vectors were contained and patched.

Injective is explicit that the core blockchain, consensus mechanism, native INJ asset, user balances and staked assets were not compromised. On the official account, this is an application-layer exploit rather than an L1 consensus exploit.

Why the network-halt wording is disputed

Bithumb issued a formal notice saying INJ deposits and withdrawals were suspended because block production had stopped. Independent archive-node analysis also identified a multi-hour gap between blocks.

Injective rejects the “chain halt” characterization and says the accelerated upgrade simply took longer than expected across validators and infrastructure. CEXVia therefore treats the operational description as conflicting evidence rather than choosing one side.

Leading exploit mechanism and loss estimate

Independent technical analysis describes an attack involving a deprecated oracle and binary-options refund logic. Some analyses report hundreds of malicious markets and estimate roughly $4.9M was extracted and consolidated into about 1,980 ETH.

Injective has not published a final technical post-mortem confirming that mechanism or loss. The amount remains Developing / On-chain, not Official.

Why exchange suspensions matter

When exchanges disable deposits and withdrawals, INJ liquidity becomes segmented. Users cannot move assets between self-custody and the venue, arbitrage becomes harder and local prices can diverge.

That is a genuine asset-access risk even if the base chain is ultimately judged secure.

Evidence Status

Confirmed: application exploit, accelerated upgrade, attack-vector patching, temporary validator jailing, exchange suspensions, Injective statement that core chain/user funds remained secure.

Developing: ~$4.9M estimate, ~1,980 ETH, deprecated-oracle/refund path, malicious-market count.

Conflicting: Injective disputes “chain halt”; Bithumb cited stopped block production; archive-node analysis observed a multi-hour block gap.

Risk Assessment

High. The exploit and operational disruption are material, but there is no verified base-chain compromise or broad loss of user balances.

What to Watch Next

Official post-mortem; final confirmed loss; exact block timeline; exchange reopenings; attacker ETH movement; oracle/binary-options safeguards; validator recovery; compensation.

FAQ

Was the Injective blockchain hacked?

Injective says the exploit was limited to applications and did not compromise the core chain.

Did block production stop?

Bithumb and archive-node evidence indicate a material interruption, while Injective disputes the halt characterization.

How much was lost?

Approximately $4.9M is an independent estimate, not an official final loss.

Were INJ user balances stolen?

Injective says native INJ, user funds and staked assets remained secure.