arrow back

Injective Stopped Blocks for 4 Hours Over Possible Hack

01 Sep 2026

Injective Stopped Blocks for 4 Hours Over Possible Hack

On August 31, 2026, Injective did not process blocks for 3 hours 42 minutes, and the likely loss from the attack reached $4.9 million. This hit traders and those working with binary options. The incident occurred at block 181,027,006.

According to onchain researchers, the attacker may have used a flaw in the logic of insurance funds and market_id to withdraw more than was deposited. Later, on September 1, the project called the event an «accelerated network upgrade» after an exploit in a limited number of binary options applications. That pause raised the main question: what actually broke?

What exactly happened to Injective?

The problem started with the binary options market. That is where, according to researchers, the attacker created a scheme with multiple subaccounts and opened and closed long and short positions.

In this way, the attacker forced the protocol to calculate larger payouts than were actually in the system. This is no longer a minor bug. It is a direct financial hole.

The key weakness, as described in reports, was that market parameters were concatenated without separators. Because of this, different data sets could receive the same market_id. The system then mixed up assets. For example, USDC could be incorrectly linked to an insurance fund in INJ.

In one example cited, about 44,099 USDC was deposited and 62,667 USDC was withdrawn. The difference was approximately 18,568 USDC. Other estimates put the total loss between $4.6 million and $4.9 million. The Gate US research also mentioned 299 short-lived instant binary options markets over 19 hours. This looks less like a coincidence and more like a clearly structured scheme.

Why does this matter for network users?

Because a 3 hour 42 minute halt means not only a pause in block processing. It also creates risk for those waiting on transfers, arbitrage, or position closures. When the network is stuck at block 181,027,006, time in crypto becomes very expensive.

There is also an important nuance. Researcher Rarma, cited by CryptoDnes, wrote that no rollback occurred. After the pause, the network moved from block 181,027,006 straight to 181,027,007. In other words, confirmed transactions were not rolled back.

For users, this means one simple thing: even a short technical outage does not always protect against the consequences of an attack that has already happened. And another point, the team’s silence only poured fuel on the fire.

Market reaction

There was no public reaction from the team at first. But later Injective said that consensus, INJ, staking, and user funds were not affected, and that the attack vector had already been contained and patched. In stories like this, the market looks not only at the exploit itself, but also at whether it affected the network’s base layer.

“Consensus, INJ, staking, and user funds were not compromised,” Injective said in its later statement.

Another benchmark for scale: according to CoinMarketCap, INJ’s market capitalization was about $485.19 million, and daily trading volume was about $74.46 million. So a $4.9 million loss equals roughly 1.01% of that market cap.

That is not much for the entire network. But for a single application, it is very noticeable.

  • The network outage lasted 3 hours 42 minutes.

  • The incident occurred at block 181,027,006.

  • The estimated loss reached $4.9 million.

  • One example showed a withdrawal of 62,667 USDC after a deposit of 44,099 USDC.

  • According to Gate US, the attack affected 299 short-lived binary options markets over 19 hours.

  • Later, Injective said the base network was not affected.

What does this mean for investors?

For INJ holders, the main takeaway is simple: not every exploit hits the whole network equally. Here, the problem looks more like a failure in a specific application than a collapse of the chain itself. But the market still punishes trust.

Especially when the network is down for almost 4 hours. There is also a broader lesson for the entire DeFi segment.

If the market mechanics with market_id and insurance funds are built carelessly, the attacker is not looking for hacker magic, but for a plain calculation error. This is an old scenario. That is why users need to look not only at the token, but also at how the specific product built on top of it works.

For those holding Injective assets or trading on related platforms, the practical takeaway is one: after such incidents, it is worth monitoring official updates and withdrawal status. If you need to quickly sell Bitcoin on Monobank, do it through a service with a clear transaction status.

Frequently asked questions

How long did the Injective outage last?

According to the source, the network did not process blocks for 3 hours 42 minutes. The halt occurred at block 181,027,006. Later, third-party services recorded a full recovery already on September 1.

Were user funds and staking affected?

Injective said that consensus, INJ, staking, and user funds were not compromised. The issue involved a limited number of binary options applications. In other words, the problem was in a specific attack vector, not in the entire chain.

What was the scale of the loss?

Estimates ranged from $4.6 million to $4.9 million. Later, researcher Paddy-earthling reported about $4.9 million and the conversion of stolen USDC into approximately 1,980 ETH. That is a fairly clear signal of the seriousness of the attack.

The Injective story is a simple reminder: even a strong network can stumble on a single application. And users are better off watching not only the token, but also the state of the infrastructure around it.

This material is not financial advice. Cryptocurrency trading involves significant risks. Part of this text was prepared with the help of artificial intelligence based on public sources and reviewed by our editorial team.