Injective Exploit Drains $4.9M and Halts Network
The Injective exploit reportedly drained about $4.9 million and halted the network for roughly four hours on 1 September 2026. The claims have not been independently confirmed by Injective. Blockchain monitor Paddy-earthling said an attacker used Frontrunner, a disabled but still registered oracle, to create 299 binary-options markets. With its price feeds emptied, the markets triggered a “no-price refund” mechanism that allegedly paid about twice the intended amount. The attacker reportedly converted the stolen USDC into around 1,980 ETH and transferred the funds to a previously inactive Ethereum wallet. Injective is said to have covered the protocol shortfall, but the repair allegedly occurred without a governance vote or detailed public explanation. The Injective exploit highlights risks in oracle lifecycle management, market-creation permissions and refund logic. Traders should monitor official updates, exchange and bridge flows, and wallet activity. The incident could increase short-term volatility and risk aversion around INJ and related DeFi tokens.
Bearish
The reported Injective exploit is bearish for INJ because it creates direct concerns about protocol security, operational controls and incident transparency. In the short term, a four-hour network halt, the alleged $4.9 million loss and uncertainty over the repair process could trigger selling, wider spreads and higher volatility as traders reduce exposure. Transfers of the stolen funds or signs of further losses could add pressure, while official confirmation, a credible post-mortem and stronger safeguards could limit the downside. Over the longer term, unresolved oracle and derivatives-market risks may weaken confidence in Injective and reduce network activity. Governance reforms, improved oracle controls and transparent compensation could help restore trust, but until those measures are demonstrated, the risk-reward profile for INJ remains negative.