Injective, the layer-1 blockchain focused on on-chain financial markets, is facing questions about both its emergency response and its accounting of a recent exploit, after researchers estimated that about $4.9 million was bridged to Ethereum during an attack on binary-options markets.

Four Hours Without a Block

Ledger data shows the chain produced block 181027005 at 16:09:59 UTC on August 31, after which block production stopped for roughly four hours. On-chain researcher Earthling Paddy noted that one earlier block alone took about 37 minutes, and infrastructure provider QuickNode also reported a stalled block height during the incident.

On September 1, the Injective Foundation characterized the event differently: the blockchain was "upgraded, not halted," it said, adding that consensus, native INJ, and staked assets were never compromised. The foundation attributed the longer-than-expected downtime to validators and ecosystem infrastructure moving to the accelerated emergency release.

The response had visible side effects. Some validators were temporarily jailed after missing the required upgrade window, and exchanges including Coinbase and Coins.ph temporarily restricted INJ transfers.

Where the Vulnerability Sat

The foundation described the attack as affecting "a small number of ecosystem applications using binary-options markets." Paddy disputed that framing while crediting the team for containing the exploit and keeping staked funds safe.

According to the researcher, the attack used messages from Injective's native exchange and insurance modules, and the emergency release — v1.20.3-safeharbor.1 — patched the chain's core code by adding an insurance-fund denomination check and disabling binary-options settlement on mainnet. That would place the vulnerable logic inside protocol modules used by applications, rather than solely within application code.

Open Questions

Researchers associated with Defimon estimated that roughly $4.9 million was bridged to Ethereum during the exploit. Paddy said approximately that amount remained in an attacker-linked wallet and had not moved.

Injective has not yet published a full technical postmortem. Key items remain undisclosed: the total amount drained, how the loss will be allocated, and whether an ecosystem pool that now appears replenished was restored by the foundation, developers, or another participant. CEO Eric Chen said Injective users "aren't affected" and that the incident was contained before further harm, but the company's statement that users were unaffected sits alongside the unresolved loss-allocation questions researchers have raised.

Until the postmortem lands, the incident leaves two findings intact: Injective's consensus and staked INJ were not compromised — and its core modules were patched, mid-chain, in response to a multi-million-dollar exploit.

TrustGrade tracks the security posture of DeFi protocols and chain infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.