Binary-options settlement bug exploited on Injective for ~$4.9M; attacker bridged funds to Ethereum where they remain stationary.
Security & Exploits ·
A binary-options settlement bug on Injective was exploited to withdraw approximately $4.9 million, according to on-chain analysis. The attacker bridged the funds to Ethereum using the Cross-Chain Transfer Protocol (CCTP), where they were swapped to ETH and remain stationary in a single address. The exploit was not an oracle or bridge hack, but rather a vulnerability in how binary-options markets settled when prices were unavailable.
The attacker created multiple instant binary-options markets on Injective with themselves as the administrator and operator of a self-run oracle. Markets were configured with expiration and settlement timestamps approximately ten seconds apart, minimal fees, and uncapped notional value—designed to trigger a no-price refund settlement path. The attacker then deposited USDC into insurance funds and self-matched buy and sell orders from their own subaccounts, creating a loop that paid out roughly twice the amount deposited per cycle until the chain halted.
The exploit continued for roughly thirty minutes before failing when network congestion caused block times to extend to approximately thirty-eight minutes, expiring the settlement timestamp mid-attack. Block 181,027,005 recorded the final failed attempt with error code 72. Validators halted the chain shortly after. An on-chain bounty negotiation message appeared approximately thirty minutes post-halt, though no official statement from Injective has been released regarding the incident.