BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Injective Exploit Drains $4.9M as Ontology Halts Mainnet

An attacker built a fake oracle on Injective and drained insurance funds through its refund path. The chain seized under the attack’s own load before validators stopped it. Ontology stopped i

AnonymousCryptoCompass newsroom
September 1, 2026
8 min read
NEWS
Injective Exploit Drains $4.9M as Ontology Halts Mainnet
CryptoCompass editorial visual for defi coverage.
  • An attacker built a fake oracle on Injective and drained insurance funds through its refund path.
  • The chain seized under the attack’s own load before validators stopped it.
  • Ontology stopped its own chain as a precaution and reported no loss of user assets.
  • Korean exchanges are reported to have suspended ONT transfers during the pause.

Two Layer-1 networks stopped producing blocks within the same window on Aug. 31, and the coincidence was enough for most coverage to treat them as one story. They were not. Injective, the finance-oriented chain incubated by Binance, went dark for roughly 3 hours and 42 minutes while an attacker pulled value out of its binary options module, taking roughly $4.9 million before the chain seized. Ontology, an identity-focused public blockchain, stopped its own mainnet at block height 20,770,893 after its development team flagged a potential security concern during a daily check, and lost nothing at all. Injective did not stop itself. It buckled under the attack until validators had no choice. Ontology stopped itself on purpose, before anyone had taken anything.

Halted under load Injective (INJ) Downtime~3 h 42 minFunds lost~$4.9M from insurance fundsRestartAfter block 181,027,005RollbackNoneExchange actionNo freeze reported Preventive halt Ontology (ONT) Downtime~5 h 06 minFunds lostNonePaused atBlock 20,770,893RollbackNot applicableExchange actionBithumb, Upbit reported suspensions

The attacker built the oracle, named it, and pointed it at nothing

Independent researcher Paddy-earthling, who discloses holding INJ, reconstructed the attack from the chain’s own transaction record and published it hours after the halt. Injective has issued no technical post-mortem of its own, so the account below rests on that analysis rather than on anything the team has confirmed.

Frontrunner was not abandoned infrastructure that someone forgot to remove. The attacker created it. Using MsgInstantBinaryOptionsMarketLaunch, they spun up a binary options market with themselves as admin and attached a self-run oracle they named Frontrunner, whose symbol was NO_PRICE_FOR_REFUND_P44_USDC. Expiration and settlement timestamps sat roughly ten seconds apart, fees were set at 1e-6, and notional was uncapped. Every parameter pointed in one direction: a market built to settle instantly into the no-price refund path and nowhere else.

The rest was mechanical. The attacker created an insurance fund, deposited USDC, then bought and sold both sides of the market from their own subaccounts at price 0.10 and quantity 1400. No counterparty existed at any point. In the roughly thirty-minute window the public indexer returned, deposits of 105,199 USDC produced withdrawals of 204,699 USDC. Twice out for once in, repeated in single atomic transactions from 14:59 UTC, roughly seven cycles before the chain stopped.

What ended the attack was not a defence. The chain, buckling under the load, slowed to block times of around 38 minutes, which meant the attacker’s own ten-second settlement stamp expired before their transaction could land. The final attempt failed in block 181,027,005 with error code 72, settlement timestamp is in the past. Validators halted immediately afterward, and the fix landed as a commit to injective-core rather than a governance-gated upgrade. The exploit degraded the network badly enough to break itself.

Proceeds moved out through CCTP to Ethereum, were swapped into ETH on Uniswap, and 1,861 ETH came to rest in a single address. The Injective account inj10ykxh78wvp8da6q8xfck3tufl0ux8sp8rulp7p derives its exchange subaccounts from Ethereum address 0x792c6bf8ee604edee807327168af89fbf863c027, the same address that bridged the funds out, which places the entire operation with one actor across both chains. The parked ETH has not moved since.

Ontology’s story has no mechanics of this kind because there was no exploit to reconstruct. The foundation described the trigger as a vulnerability identified internally, and it froze the chain in coordination with validators before any patch touched a live network. That is the conservative sequence, and it costs uptime instead of capital.

Anyone could launch a market and appoint its own price source

The dollar figure is recoverable in the sense that insurance funds can be replenished. The design question is harder to settle. Injective let a single account create a derivatives market, appoint itself admin, register its own oracle as the price source, and set the expiration and settlement window, all inside one transaction and with no sanity check on whether those parameters made economic sense. Ten seconds between expiry and settlement is not a plausible market. Uncapped notional on a freshly created contract is not a plausible market either. Nothing in the module asked.

Injective co-founder Eric Chen said on X that the base layer and INJ tokenomics were unaffected, which is accurate as far as it goes. The chain resumed after block 181,027,005 without a database rollback, meaning no user transactions were reversed and no state was rewritten. Consensus held. What failed was an application module sitting on top of consensus, and that distinction is real even if it offers little comfort to whoever was underwriting those insurance funds.

Marketing posts kept running while $4.9 million left the system

While the drain was underway, Injective’s primary channels continued publishing standard promotional content before the incident was addressed directly, and that sequencing is what community critics fixed on. The gap between what operators say during an incident and what the wallets show has run through most of this year’s failures, including the BitMart shutdown, where the founder denied an exit scam while balances drained. Ontology took the opposite route, announcing the pause itself and stating that it had found no evidence ONT, ONG or other user assets were lost or compromised. Neither approach changes the on-chain outcome. Both shape how quickly counterparties decide whether to keep capital on a chain. 

How the two halts unfolded AUG. 31, 14:59 UTC Attacker launches an instant binary options market with themselves as admin and a self-run oracle named Frontrunner. AUG. 31 – THE LOOP Self-matched trades run roughly seven cycles; 105,199 USDC deposited returns 204,699 USDC withdrawn. AUG. 31, 16:09 UTC – HALT Block times stretch to roughly 38 minutes; the attacker’s final attempt fails in block 181,027,005 and validators stop the chain. AUG. 31 – PATCH Fix lands as a commit to injective-core; the chain resumes after about 3 h 42 min with no rollback. AUG. 31 – EXIT Proceeds bridge via CCTP to Ethereum, swap into ETH on Uniswap, and 1,861 ETH settles in a single wallet. AUG. 31 TO SEPT. 1 Ontology pauses mainnet at block 20,770,893; Bithumb and Upbit are reported to restrict ONT, ONG and MBL transfers. 

A frozen chain breaks arbitrage before it breaks sentiment

On-chain ONT and ONG cannot move at all while the mainnet is paused, and Bithumb and Upbit are reported to have suspended deposits and withdrawals for ONT, ONG and MovieBloc the same day. Balances already sitting on an exchange that has not paused remain tradeable. Everything in a self-custodied wallet does not. That split is what breaks arbitrage between venues for the duration, and thin books tend to produce price prints that look worse than the underlying situation.

For Injective, the practical question is whether the insurance funds get replenished from treasury, from fees, or not at all. Derivatives venues depend on the credibility of their backstop, and market makers quoting size on a platform will size down until they know which of those three answers applies.

Coordinated halts are becoming a tool rather than a confession

Both chains demonstrated that stopping block production is now treated as a normal incident-response mechanism, and both restarted without rewriting state. That reduces the stigma attached to pulling the emergency handle, which is arguably healthy for the sector. It also sets an operational expectation that a validator set can be assembled, aligned and restarted within hours, and not every network with a distributed validator base can actually deliver that under pressure. That capability belongs in the same calculation protocols run when they decide between operating their own chain and renting throughput from someone else’s, as Aave did with Monad, because a team that halts its own network needs a validator set willing to answer at 16:09 UTC.

Injective’s exploiter address remains funded and static on Ethereum, and analytics firms are tracking it. Should those funds move toward a mixer or a centralized venue, the response window closes quickly, which is why the next meaningful development in this story is more likely to come from a blockchain forensics account than from either project’s official channel. Ontology’s own follow-up on Sept. 1 described the network as having been targeted, which shifts its halt closer to Injective’s than the first day’s framing suggested.

The post Injective Exploit Drains $4.9M as Ontology Halts Mainnet appeared first on ETHNews.