Main takeaway: Injective paused for ~4 hours after a binary options exploit stole ~$4.9M by abusing a disabled but registered oracle. Attacker created 299 markets pointing to that oracle, triggered a “no price refund” bug for ~2x payout, then swapped USDC for ~1,980 ETH now held in one inactive wallet. Injective posted marketing during the outage, made core chain code private, and patched the protocol without public audit, governance vote, or full disclosure; funds have been replenished at protocol level. Reporter holds INJ long.
PANews 9月1日消息,X平台用户Paddy-earthling披露,Injective今日因二元期权漏洞暂停运行约4小时,攻击者利用一个已停用但仍注册的预言机(Frontrunner)盗取约490万美元。该预言机的数据源早已清空,攻击者创建299个市场指向该预言机,因无法获取价格触发“无价格退款”机制,攻击者利用该机制漏洞获约2倍赔付,随后将USDC兑换为约1,980枚ETH(约490万美元),目前存放在一个未发送过任何交易的以太坊钱包中。 Paddy-earthling指出,攻击发生后,Injective官方X账号照常发布营销内容,只字未提链已暂停。jective已将核心链代码设为私有,但攻击者通过公开SDK发现漏洞,此举反而排除了白帽和审计人员。资金缺口已在协议层被填补,但修复过程无治理投票、无公开说明,无法验证。攻击者目前将所有资金归集到一个钱包未动,疑似在权衡白帽和解提议。作者披露其持有INJ多头仓位。