Nearly $5 million in losses and downtime. Blockchain Injective under the microscope – Bitcoin.pl

Key conclusions

  • Injective stopped block production for nearly four hours as part of its response to the $4.9 million leak.
  • The Injective Foundation classified the event as an update, but an independent researcher demonstrated fixes in core network modules.
  • Validators have been temporarily suspended and Coinbase and Coins.ph exchanges have suspended cryptocurrency transfers.

Injective stopped block production for almost four hours on August 31 at 16:09 UTC in response to the $4.9 million attack. The network team released a safe mode version of the code v1.20.3-safeharbor.1 which disabled binary options settlement at the native level. Although official announcements provide information about the planned upgrade of the system version, technical researchers point to direct intervention in the core protocol code.

DBCrypto@DBCrypt0

Injective trying to cover up a protocol issue? 🤨 Yesterday the foundation said the blockchain was “upgraded, not halted” On-chain data shows the blockchain stopping for 3h 42m But they want everyone to believe an upgrade, which was unannounced, took longer than expected

Read 8 replies

Injective network downtime and infrastructure response

Analysis of the transaction register indicates that the network stopped at block number 181027005. One of the blocks preceding it forced a 37-minute wait for approval. QuickNode, which provides infrastructure for nodes, confirmed the suspension of data synchronization at the same height.

The quick implementation of the new software version caused confusion among network operators. Some validators did not manage to update the nodes within the designated time window. As a result, the consensus mechanism automatically placed them in a state of suspension (jailed), which temporarily excluded them from validation. The Coinbase and Coins.ph exchanges responded by immediately suspending deposits and withdrawals of the INJ cryptocurrency.

The key point of contention surrounding the Injective architecture

The official announcement states that the attack only affected external applications from the binary options ecosystem. On-chain researcher Earthling Paddy disagrees with this position. He showed that the attack vector used direct messages from native stock exchange and insurance modules belonging to the first layer itself.

Emergency patch v1.20.3-safeharbor.1 forced an insurance fund denomination check. This means a lack of proper verification in the core itself, not in the applications built on it.

A suspicious Ethereum wallet still holds the stolen $4.9 million in transferred ETH funds. These funds have not been transferred in any way since they were transferred through the bridge.

Injective CEO Eric Chen commented on the situation, assuring on the X platform that users’ funds remained safe. So far, however, the team has not explained where the funds that replenished the empty pool of the ecosystem came from. The lack of publication of a full technical report (postmortem) makes it difficult to assess whether the vulnerability was exploited elsewhere in the network.

Effects on the exchange rate and the security of the consensus

Despite technical problems, the consensus algorithm itself, the native INJ currency and the pledged staking assets were not affected. However, the asset’s price fell by approximately 3% within 24 hours of the event, reaching USD 4.74.

Injective announces the introduction of additional checking functions and continuous monitoring. This event clearly demonstrates the risks associated with connecting exchange modules directly to the underlying blockchain layer. The interruption in network operation also undermines declarations of uninterrupted operation, calling into question the authentic reason for suspending the blocks.