Injective Network Hit by $4.9M Exploit and Mainnet Outage
The Injective Network suffered a $4.88 million exploit on August 31, leading to a nearly four-hour mainnet outage. The attack targeted the permissionless system designed for creating and settling binary options markets.
The attacker created 299 short-lived markets using an oracle configured to fail at providing the necessary price during settlement. When a valid price was missing, the protocol defaulted to a refund mechanism, which was exploited to extract more collateral than was originally deposited.
Analysis indicates that the attacker traded between their own sub-accounts, simultaneously holding long and short positions. Once the refund mechanism was triggered, they were able to withdraw approximately double the initial capital across separate cycles.