Wednesday, September 2, 2026

Injective, a layer-1 blockchain network, produced no new block for nearly four hours during an emergency response to an exploit that researchers traced into core modules.

On September 1, the foundation stated the blockchain was “upgraded, not halted,” affirming that its consensus, native INJ token, and staked assets were never compromised. Researchers characterized the incident as affecting only a small subset of ecosystem applications using binary-options markets.

On-chain analyst Paddy challenged both characterizations, while crediting Injective for containing the exploit and preserving staked funds. The ledger indicates block 181027005 occurred at 16:09:59 UTC on August 31 before block production ceased for approximately four hours. Paddy noted that a single prior block typically took about 37 minutes, and infrastructure provider QuickNode also reported a stalled block height throughout the episode.

Injective explained that the accelerated upgrade exceeded expectations as validators and ecosystem infrastructure transitioned to the emergency release. Several validators were briefly paused for failing to meet the required upgrade window, while major exchanges such as Coinbase and Coins.ph implemented temporary transfer restrictions.

According to CryptoSlate data, INJ was trading around $4.80 as of press time, down roughly 3% over the preceding 24 hours.

Researcher disputes where the vulnerability sat

Paddy further questioned Injective’s characterization of the exploit as limited strictly to ecosystem applications.

The signal, before the noise.

Manitra Chain Restored Online But Silent Code Changes Raise Developer Concerns

While Injective has not yet issued a comprehensive technical postmortem, its statement affirmed that the relevant attack vector had been contained and remediated. The foundation announced the addition of stronger invariants, real-time monitoring capabilities, and additional safeguards.

Researchers estimate approximately $4.9 million was bridged to Ethereum during the exploitation event. Paddy indicated that roughly that same amount remained trapped in the attacker‑linked wallet and had not yet been recovered.

The ultimate loss allocation remains ambiguous. Injective has not disclosed the precise total eventually withdrawn, nor clarified which party might have covered any shortfall, or whether an ecosystem pool that now appears replenished was restored by the foundation, developers, or another participant.

Consequently, Injective maintains that end‑users were unaffected, and its chief executive issued an accompanying statement via X.

“Injective users aren’t affected and we’ve been helping the team on recovery. Always sad to see exploits happening in the ecosystem but we’re glad that the incident was contained before further harm was done.”

Nevertheless, the event entails two distinct findings: Injective’s consensus mechanism and staked INJ holdings were not compromised, while its emergency response nevertheless coincided with a multi‑hour interruption in block production and necessitated a core‑code patch.

Source link

Exit mobile version