XIYU.NEWS EVENTS

Layer-1 blockchain Injective halts for 4 hours to stop $4.9M exploit, calls it an upgrade

MonitoringCryptoSecurity incidentFirst tracked 2026-09-02Last changed 2026-09-02

Current outcome

On Sept. 1, Injective paused block production for nearly four hours while validators deployed an emergency patch after an exploit drained roughly $4.9 million via binary-options markets. The foundation described the event as an 'upgrade, not halted' and said consensus, native INJ, and staked assets were not compromised. The incident shows that even a major layer-1's core modules can contain exploitable logic, and that containing an attack may require halting the chain, which raises transparency and decentralization questions. It matters for Injective users, validators, and the broader L1 security and emergency governance discussion. Researcher Earthling Paddy disputed the foundation's claim that the exploit only affected ecosystem applications, noting the attack used messages from Injective's native exchange and insurance modules, and that the emergency patch added an insurance-fund denomination check and disabled binary-options settlement on mainnet. Block 181027005 at 16:09:59 UTC on Aug. 31 was followed by roughly four hours of halted production; some validators were temporarily jailed and exchanges such as Coinbase and Coins.ph restricted transfers.

Progress timeline

1 material updates
  1. #01
    Initial2026-09-02 11:50 · publication time

    Layer-1 blockchain Injective halts for 4 hours to stop $4.9M exploit, calls it an upgrade

    On Sept. 1, Injective paused block production for nearly four hours while validators deployed an emergency patch after an exploit drained roughly $4.9 million via binary-options markets. The foundation described the event as an 'upgrade, not halted' and said consensus, native INJ, and staked assets were not compromised. The incident shows that even a major layer-1's core modules can contain exploitable logic, and that containing an attack may require halting the chain, which raises transparency and decentralization questions. It matters for Injective users, validators, and the broader L1 security and emergency governance discussion. Researcher Earthling Paddy disputed the foundation's claim that the exploit only affected ecosystem applications, noting the attack used messages from Injective's native exchange and insurance modules, and that the emergency patch added an insurance-fund denomination check and disabled binary-options settlement on mainnet. Block 181027005 at 16:09:59 UTC on Aug. 31 was followed by roughly four hours of halted production; some validators were temporarily jailed and exchanges such as Coinbase and Coins.ph restricted transfers.

    Source evidence: CryptoSlate

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.