Refreshed 5h ago· updates every 6h

Injective Binary Options (2026) — Crypto Hack

Ongoing
Aug 31, 2026·
InjectiveEthereum
Amount Stolen
$4.9M
~1,980 ETH (~$4.9M)
Recovered
$0

Attacker exploited a deactivated but still registered 'Frontrunner' oracle on Injective's binary options markets, creating 299 markets that triggered a no-price refund mechanism paying ~2x, stealing ~$4.9M.

Summary

Attacker exploited a deactivated but still registered 'Frontrunner' oracle on Injective's binary options markets, creating 299 markets that triggered a no-price refund mechanism paying ~2x, stealing ~$4.9M.

How It Was Compromised — DeFi via Oracle Manipulation / No-Price Refund Flaw

DeFiOracle Manipulation / No-Price Refund Flaw

On August 31, 2026, Injective halted block production for ~3 hours 42 minutes (block height recovered from 181,027,006 to 181,027,007 with no rollback) after an attacker exploited a binary options vulnerability. The attacker used a deactivated but still registered oracle called 'Frontrunner' whose data source had long been emptied, created 299 markets pointing to it, and triggered a no-price refund mechanism that paid out roughly double the expected amount. The attacker repeatedly exploited Injective's insurance fund and permissionless binary options market creation mechanism. The protocol-layer funding shortfall was filled via an emergency patch without a governance vote. The attacker consolidated ~1,979.8 ETH (~$4.88M) into a single Ethereum wallet that has never transacted, reportedly weighing a whitehat settlement.

Fund Flow & Laundering Analysis

Stolen USDC was swapped for ~1,980 ETH and moved to an Ethereum wallet that has never sent any transactions; funds remain consolidated there.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.