T
iTokenly

Injective (binary options settlement) hack — August 2026

Verified — 3 sourcesLast checked September 7, 2026

Incident facts

Date of incident
Target typeBlockchain or validator set
Loss$4,900,000Price at time of incident
MethodContract logic errorMarket identifiers were built by concatenating five fields with no separators or length prefixes, letting an INJ-denominated insurance fund collide with the identifier of a USDC-denominated binary options market, so a dust balance in one token was read as covering a dollar shortfall in another
ChainsOther
OutcomeUnresolved

What happened

Injective's layer-1 stopped producing blocks for three hours and forty-two minutes on 31 August 2026 while its validators shipped an emergency patch. Researchers put the amount taken at about $4.9m.

The defect was in how the chain names its markets. A market identifier was derived by concatenating oracleType, ticker, quoteDenom, oracleSymbol and oracleProvider with no separators and no length prefixes, so different combinations of fields could produce the same identifier. The attacker used that to make an INJ-denominated insurance fund collide with the identifier of a USDC-denominated binary options market. At settlement the chain looked up the fund under that identifier, found a trivial INJ balance, and treated it as sufficient cover for a dollar-denominated shortfall, skipping the haircuts that exist for precisely this case and releasing full withdrawals.

Getting there took the rest of the setup. Binary options markets could be created permissionlessly, and the attacker created 299 of them, each pointed at an oracle they controlled and had configured never to return a price. A missing price at settlement falls through to a refund path. Expiry and settlement timestamps were set seconds apart, and trades were self-matched between the attacker's own subaccounts at prices they chose. One documented cycle turned roughly 105,000 USDC of deposits into more than 204,000 USDC of withdrawals, and the cycle was repeated.

Block production had already degraded to intervals of about thirty-seven minutes before it stopped after block 181,027,005 at 16:09:59 UTC. The chain advanced exactly one block between 16:10 and 19:52 UTC. The emergency release v1.20.3-safeharbor.1 added an insurance-fund denomination check and disabled binary-options settlement on mainnet. Nothing was reversed, a deliberate contrast with Cronos, which the previous day discarded 10,961 blocks to undo the Tectonic theft recorded elsewhere in this registry.

The $4.9m is DefimonAlerts's on-chain estimate, measured as roughly 1,980 ETH bridged to Ethereum during the incident; the researcher Paddy noted that approximately that amount was still sitting unmoved in the attacker-linked wallet. PeckShield's separate monthly tally put the figure at $4.8m. Injective has confirmed neither.

On 1 September the foundation said the chain had been upgraded rather than halted, that consensus, native INJ and staked assets were never compromised, and that the impact was confined to a small number of ecosystem applications using binary-options markets. CEO Eric Chen said Injective users were not affected. No full technical post-mortem has been published, no final loss figure has been given, and it has not been said who absorbed the shortfall. Metaverse Post additionally reported that the injective-core and injective-chain repositories were taken down from GitHub; that account rests on that publisher alone.

A separate matter, recorded here so that the two are not merged: in June 2026 a compromised account published a malicious build of the Injective TypeScript SDK to npm that hooked key-derivation functions to exfiltrate private keys. It was live for under an hour, was downloaded roughly 310 times, and no theft was ever reported. It falls below this registry's threshold and has no entry.

Sources

  1. CryptoSlateSecondary · retrieved 2026-09-07
  2. Metaverse PostSecondary · retrieved 2026-09-07
  3. crypto.news, PeckShield monthly tally at $4.8mSecondary · retrieved 2026-09-07

Changes to this entry

  • Filed as a single-source lead from PeckShield's monthly tally, with no date, mechanism or confirmation from Injective. To be verified, corrected or removed once Injective or a second independent publisher describes the incident.
  • Promoted from reported to verified. CryptoSlate and Metaverse Post independently described the incident with on-chain detail, establishing the date, the halt of 3 hours 42 minutes after block 181,027,005, and the mechanism: an identifier collision between an INJ-denominated insurance fund and a USDC-denominated binary options market, reached through 299 permissionlessly created markets with a deliberately silent oracle. The amount was moved from PeckShield's $4.8m monthly-tally line to DefimonAlerts's $4.9m on-chain estimate, with both stated in the summary. The vector changed from unstated to a logic error and the approximate-date flag was cleared. The mechanism details previously recorded as unattributed rumour are now sourced and stated as fact.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Injective (binary options settlement) hack — August 2026", iTokenly, accessed 2026-09-07, https://itokenly.com/hacks/injective-august-2026
https://itokenly.com/hacks/injective-august-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.