Injective Binary Options (2026) — Crypto Hack
OngoingAttacker exploited a deactivated but still registered 'Frontrunner' oracle on Injective's binary options markets, creating 299 markets that triggered a no-price refund mechanism paying ~2x, stealing ~$4.9M.
Summary
Attacker exploited a deactivated but still registered 'Frontrunner' oracle on Injective's binary options markets, creating 299 markets that triggered a no-price refund mechanism paying ~2x, stealing ~$4.9M.
How It Was Compromised — DeFi via Oracle Manipulation / No-Price Refund Flaw
On August 31, 2026, Injective halted block production for ~3 hours 42 minutes (block height recovered from 181,027,006 to 181,027,007 with no rollback) after an attacker exploited a binary options vulnerability. The attacker used a deactivated but still registered oracle called 'Frontrunner' whose data source had long been emptied, created 299 markets pointing to it, and triggered a no-price refund mechanism that paid out roughly double the expected amount. The attacker repeatedly exploited Injective's insurance fund and permissionless binary options market creation mechanism. The protocol-layer funding shortfall was filled via an emergency patch without a governance vote. The attacker consolidated ~1,979.8 ETH (~$4.88M) into a single Ethereum wallet that has never transacted, reportedly weighing a whitehat settlement.
Fund Flow & Laundering Analysis
Stolen USDC was swapped for ~1,980 ETH and moved to an Ethereum wallet that has never sent any transactions; funds remain consolidated there.