- The Injective Layer 1 network stopped processing blocks for three hours and 42 minutes on Aug. 31, 2026.
- Onchain analysts said a suspected attacker may have exploited binary-options mechanics to withdraw nearly $5 million.
- Estimates placed the potential losses between $4.6 million and $4.9 million.
- The Injective team had not commented on the incident at the time of writing.
The Injective Layer 1 network stopped processing blocks for three hours and 42 minutes on Aug. 31, 2026, amid reports of a possible hack. Onchain analysts said a suspected attacker may have manipulated the protocol’s binary-options mechanics and withdrawn nearly $5 million.
The network halt began at block height 181,027,006, according to block history available through the Injective Explorer.
The Injective team had not commented on the situation at the time of writing. Analyst Paddy-earthling noted that promotional posts continued to appear on the project’s official page during the disruption, drawing criticism of the team.
Suspected attack mechanism
The suspected attack involved a potential flaw in how Injective’s binary markets were mapped to insurance funds.
According to researcher Yi, the attacker traded with themselves through different subaccounts. By repeatedly opening and closing long and short positions, the attacker allegedly caused the protocol to record more funds as refundable than remained in the system.
Under normal conditions, a shortfall during market settlement should have reduced payouts to users. The attacker may have bypassed that mechanism because of how the protocol constructed its market_id identifiers.
Market parameters were reportedly concatenated without separators, allowing different sets of data to produce the same identifier. This could make it possible to link a market denominated in USDC to an insurance fund denominated in INJ.
When calculating the shortfall, the protocol reportedly compared the numerical values directly without accounting for the fact that they represented different assets. A small amount of INJ could therefore be mistakenly treated as sufficient to cover a deficit denominated in USDC or another token.
The system would then avoid reducing payouts, allowing the remaining positions to receive full refunds. According to the suspected mechanism, this enabled the attacker to withdraw more than they had initially deposited.
In one cited example, approximately 44,099 USDC was deposited and 62,667 USDC was withdrawn, a difference of about 18,568 USDC.
The total damage remained unknown at the time of writing. Estimates ranged from $4.6 million to $4.9 million.
The incident followed other recent blockchain outages linked to cybersecurity incidents, including network halts involving Fogo and Cronos.
Source: Incrypted
