Tools Crypto Exploit Tracker exploit-0001
Exploit record
Injective Binary-Options Exploit and Emergency Upgrade
- Attack vector
- Smart Contract Bug
- Chain
- Injective
- Sector
- Derivatives
What happened
An attacker exploited Injective’s binary-options settlement and insurance-fund logic on 31 August 2026. Block production stopped for 3 hours 42 minutes while an emergency release, v1.20.3-safeharbor.1, was deployed. Injective’s official account described the incident on 1 September as an accelerated network upgrade and said the blockchain and INJ remained secure throughout. Co-founder Eric Chen said Injective users were not affected and that the team had helped with recovery.
The patch in commit b994d6b disables binary-options settlement on mainnet and adds a check that the insurance fund’s denomination matches the market’s quote denomination before any transfer is made, which points at a self-created market as the route in. The pause is measurable on chain: block 181,027,006 carries a timestamp of 16:10:02 UTC on 31 August and the next block, 181,027,007, carries 19:52:14 UTC, a gap of 13,332 seconds against a median block time of 0.62 seconds across the surrounding day. Injective describes that period as an accelerated upgrade rather than a halt; the two block timestamps are recorded here so a reader can weigh the wording against the chain. A second patch followed. Governance proposal 690, v1.20.3-safeharbor.2, was submitted at 16:02 UTC on 1 September, passed, and executed at block 181,295,000 at 17:43:41 UTC on 2 September, this time with block production continuing through it. Its proposal text describes targeted chain improvements and new transfer integrations, and names neither the exploit nor a security fix, which matches Injective’s practice on the December 2025 and safeharbor.1 upgrades. As of 6 September Injective has published no loss figure and no technical post-mortem, and its blog has carried three unrelated posts since, two on 2 September and one on 4 September. A third-party trace circulated on 1 September put the amount moved at roughly $4.9m, consolidated in an Ethereum address given only in truncated form; the $4.8m figure repeated since carries no separate trace behind it. Neither is confirmed by Injective and neither is counted in this log’s totals: the loss is recorded as unpublished rather than estimated.
On-chain references
- Last block before the pausesentry.exchange.grpc-web.injective.network/api/explorer/v1/b…
- First block after the pausesentry.exchange.grpc-web.injective.network/api/explorer/v1/b…
Sources
- Injective, official statement (1 September 2026)x.com/injective/status/2094784707623788664
- Eric Chen, Injective co-founderx.com/ericinjective/status/2094709402980745632
- injective-core commit b994d6b, the v1.20.3-safeharbor patchgithub.com/InjectiveFoundation/injective-core/commit/b994d6b
- Governance proposal 690, the v1.20.3-safeharbor.2 upgrade (passed 2 September 2026)lcd.injective.network/cosmos/gov/v1/proposals/690
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
