A layer-1 blockchain froze for 4 hours to stop a $4.9 million hack, then claimed it was just an upgrade
Injective, a layer-1 blockchain community, produced no new block for practically 4 hours throughout an emergency response to an exploit that researchers traced into core modules.
On Sept.1, the muse said the blockchain was “upgraded, not halted” and that its consensus, native INJ, and staked property have been by no means compromised. It described the assault as affecting a small variety of ecosystem functions utilizing binary-options markets.
On-chain researcher Earthling Paddy challenged each characterizations, whereas crediting Injective for containing the exploit and conserving staked funds protected.
The ledger shows block 181027005 at 16:09:59 UTC on Aug. 31 earlier than block manufacturing stopped for roughly 4 hours. Paddy mentioned one earlier block alone took about 37 minutes, whereas infrastructure supplier QuickNode additionally reported a stalled block peak in the course of the incident.
Injective mentioned the accelerated upgrade took longer than anticipated as validators and ecosystem infrastructure moved to the emergency launch. Some validators have been briefly jailed after lacking the required upgrade window, whereas exchanges together with Coinbase and Coins.ph briefly restricted transfers.
Data from CryptoSlate exhibits INJ buying and selling round $4.80 as of press time, down roughly 3% over the earlier 24 hours.
Researcher disputes the place the vulnerability sat
Paddy additionally questioned Injective’s description of the exploit as remoted to ecosystem functions.
He mentioned the assault used messages from Injective’s native trade and insurance coverage modules, whereas the emergency v1.20.3-safeharbor.1 release patched the chain’s core code by including an insurance-fund denomination examine and disabling binary-options settlement on mainnet.
That would place the weak logic inside a protocol module utilized by functions fairly than solely inside software code.
Injective has not but printed a full technical postmortem. Its assertion mentioned the related assault vector had been contained and patched and that the muse was including stronger invariants, real-time monitoring, and different safeguards.
Researchers estimate about $4.9 million was bridged to Ethereum in the course of the exploit. Paddy mentioned roughly that quantity remained within the attacker-linked pockets and had not moved.
The closing loss allocation stays unclear. Injective has not disclosed how a lot was in the end drained, which celebration absorbed any shortfall, or whether or not an ecosystem pool that now seems replenished was restored by the muse, builders, or one other participant.
Instead, the blockchain has maintained that its customers weren’t affected. In an X submit, Injective CEO Eric Chen said:
“Injective customers aren’t affected and we’ve been serving to the staff on restoration. Always unhappy to see exploits taking place within the ecosystem however we’re glad that the incident was contained earlier than additional hurt was executed.”
Nonetheless, the incident subsequently leaves two separate findings intact. Injective’s consensus and staked INJ weren’t compromised, whereas its emergency response nonetheless coincided with a multi-hour interruption in block manufacturing and required a core-code patch.
The submit (*4*) appeared first on CryptoSlate.

