Breaking
RUOperation Statewide Shield finds 163 missing children in FloridaRUNepal landslide and flooding death toll rises to 1,204GLOBALPrivate U.S. Job Growth Slows in August, ADP ReportsINTLRussia has been secretly aiding Iran's supersonic missile development for years, report saysPLFour people died in an accident on the A1 motorway near CzęstochowaSESabotage against German electricity infrastructure is being investigated as a possible terrorist crimeINTLBank of America VP Erin Piacenti fatally stabbed in Times Square on first week back from maternity leaveITAlex Eala triumphs in the first round of the US Open and lights up the 'Louis Armstrong Stadium'INTLParents arrested after body of missing nonverbal 5-year-old found near South Carolina beachESAn Italian family commits suicide after giving up hope for experimental treatment for their disabled daughterRUOperation Statewide Shield finds 163 missing children in FloridaRUNepal landslide and flooding death toll rises to 1,204GLOBALPrivate U.S. Job Growth Slows in August, ADP ReportsINTLRussia has been secretly aiding Iran's supersonic missile development for years, report saysPLFour people died in an accident on the A1 motorway near CzęstochowaSESabotage against German electricity infrastructure is being investigated as a possible terrorist crimeINTLBank of America VP Erin Piacenti fatally stabbed in Times Square on first week back from maternity leaveITAlex Eala triumphs in the first round of the US Open and lights up the 'Louis Armstrong Stadium'INTLParents arrested after body of missing nonverbal 5-year-old found near South Carolina beachESAn Italian family commits suicide after giving up hope for experimental treatment for their disabled daughter
BackInjective blockchain halted block production for four hours during emergency response to exploit
Injective blockchain halted block production for four hours during emergency response to exploit
Developing
CryptoSlate2 hours agoTech2 min read

Injective blockchain halted block production for four hours during emergency response to exploit

Quick Look

  • Injective's layer-1 blockchain stopped producing blocks for nearly four hours on Aug.
  • 31 during an emergency response to an exploit traced to core modules.
  • Researchers disputed the foundation's claim that the chain was 'upgraded, not halted,' noting the attack used native exchange and insurance modules.

AI-generated summary

Why It Matters

Injective is a layer-1 blockchain network focused on decentralized finance applications. The incident occurred during an emergency response to a security exploit, leading to a temporary halt in block production.

Font size

Injective, a layer-1 blockchain network, produced no new block for nearly four hours during an emergency response to an exploit that researchers traced into core modules.

On Sept.1, the foundation said the blockchain was “upgraded, not halted” and that its consensus, native INJ, and staked assets were never compromised. It described the attack as affecting a small number of ecosystem applications using binary-options markets.

On-chain researcher Earthling Paddy challenged both characterizations, while crediting Injective for containing the exploit and keeping staked funds safe.

The ledger shows block 181027005 at 16:09:59 UTC on Aug. 31 before block production stopped for roughly four hours. Paddy said one earlier block alone took about 37 minutes, while infrastructure provider QuickNode also reported a stalled block height during the incident.

Injective said the accelerated upgrade took longer than expected as validators and ecosystem infrastructure moved to the emergency release. Some validators were temporarily jailed after missing the required upgrade window, while exchanges including Coinbase and Coins.ph temporarily restricted transfers.

Data from CryptoSlate shows INJ trading around $4.80 as of press time, down roughly 3% over the previous 24 hours.

Researcher disputes where the vulnerability sat

Paddy also questioned Injective’s description of the exploit as isolated to ecosystem applications.

He said the attack used messages from Injective’s native exchange and insurance modules, while the emergency v1.20.3-safeharbor.1 release patched the chain’s core code by adding an insurance-fund denomination check and disabling binary-options settlement on mainnet.

That would place the vulnerable logic inside a protocol module used by applications rather than solely within application code.

Injective has not yet published a full technical postmortem. Its statement said the relevant attack vector had been contained and patched and that the foundation was adding stronger invariants, real-time monitoring, and other safeguards.

Researchers estimate about $4.9 million was bridged to Ethereum during the exploit. Paddy said roughly that amount remained in the attacker-linked wallet and had not moved.

The final loss allocation remains unclear. Injective has not disclosed how much was ultimately drained, which party absorbed any shortfall, or whether an ecosystem pool that now appears replenished was restored by the foundation, developers, or another participant.

Instead, the blockchain has maintained that its users weren't affected. In an X post, Injective CEO Eric Chen said:

“Injective users aren’t affected and we’ve been helping the team on recovery. Always sad to see exploits happening in the ecosystem but we’re glad that the incident was contained before further harm was done.”

Nonetheless, the incident therefore leaves two separate findings intact. Injective’s consensus and staked INJ were not compromised, while its emergency response still coincided with a multi-hour interruption in block production and required a core-code patch.

What to Watch

AI outlook — possibilities, not facts

  • Injective will release a full technical postmortem detailing the exploit and patch.

    Likely · Within weeks

Open Questions

  • What was the exact amount of funds drained in the exploit?
  • Which party absorbed any financial shortfall from the exploit?
  • Was the replenished ecosystem pool restored by the foundation, developers, or another participant?
  • Will Injective publish a full technical postmortem detailing the vulnerability and fix?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

AI-backed group spends millions on ads to defend data centers in battleground states
Developing·21 minutes ago

AI-backed group spends millions on ads to defend data centers in battleground states

Build American AI, funded by AI billionaires via super PAC Leading the Future, is spending millions on advertising in Kansas, Ohio and Wisconsin to support data center construction amid rising local opposition, which has increased to 61% nationally according to Annenberg polling, with political figures and lenders increasingly treating data center siting as a credit risk and campaign issue.

Decrypt
2 min read
Full Sail DeFi Protocol to Shut Down After Oracle Security Incident
Developing·1 hour ago

Full Sail DeFi Protocol to Shut Down After Oracle Security Incident

Full Sail, a DeFi protocol on the Sui blockchain, announced it will shut down following a security incident involving oracle provider Switchboard that led to user losses. The protocol has disabled new deposits and LP reward claims, moving regular pools to withdrawal-only mode after security checks. Full Sail will use its remaining liquidity to compensate users, with the team covering any shortfall to ensure community depositors are repaid first.

Cointelegraph
1 min read
More on this topicinjective