A security researcher known as al_f4lc0n says they found a critical vulnerability in Injective that could let an attacker directly drain any account on the chain, putting more than $500 million in on-chain assets at risk when the bug was disclosed. According to the researcher’s public account, the issue was reported through Immunefi, and Injective moved a mainnet fix to a governance vote the next day, which the researcher cites as evidence the team understood the severity. The dispute centers on the bounty payout. The researcher says Injective’s bug bounty program lists a maximum of $500,000 for critical vulnerabilities, but the project notified them of a $50,000 award after months of silence, and that payment had not yet been made at the time of the post. The technical description published by the researcher and summarized by reporting outlets says the flaw involved subaccount validation, potentially allowing an attacker to place market orders on another user’s behalf, buy worthless tokens using USDT, and bridge the proceeds out to Ethereum. The story matters because it highlights how bug bounty programs handle high-severity disclosures in DeFi, where payout decisions can shape incentives for whitehat researchers and confidence in protocol security.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Injective

Comments