We collect cookies to analyze our website traffic and performance; we never collect any personal data. Cookies Policy
Accept
AsolicaAsolicaAsolica
  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
Reading: Whitehat hacker accuses Injective of ghosting after $500M bug disclosure
Share
Font ResizerAa
AsolicaAsolica
Font ResizerAa
  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
Follow US
© 2025 Asolica News Network. All Rights Reserved.
Asolica > Blog > Crypto > Whitehat hacker accuses Injective of ghosting after $500M bug disclosure
Crypto

Whitehat hacker accuses Injective of ghosting after $500M bug disclosure

Admin
Last updated: March 16, 2026 1:02 pm
Admin
8 hours ago
Share
Whitehat hacker accuses Injective of ghosting after 0M bug disclosure
SHARE

Contents
  • The bug
  • The bounty

A whitehat hacker has gone public over a months-long feud with the group behind Injective over its response to a vital bug disclosure.

In response to the report, the vulnerability in query put $500 million in danger through a defective validation system.

The pseudonymous crypto safety researcher, who goes by the moniker al_f4lc0n, has accused Injective of ghosting them for 3 months, regardless of fixing the bug, and later lowballing the bounty payout.

The bug

The bounty hunter uploaded a full bug report back to a GitHub repository referred to as “injective-wall-of-shame.”

Within the repo’s readme, entitled “I Saved Injective’s $500M. They Pay Me $50K,” they clarify that the vulnerability allowed “any user to directly drain any account on the chain. No special permissions needed.”

The extra detailed technical report describes how a defective subaccount validation system allowed for an attacker to submit market orders on different customers’ behalf.

The bug was exploitable by an attacker making a nugatory token and making a spot market, pairing it with USDT. Each these actions are permissionless on Injective.

Then, by making a promote order of the faux token, the attacker may pressure sufferer accounts to purchase the nugatory token for USDT, “at the attacker’s chosen price.” The USDT may then be permissionlessly bridged off Injective, to Ethereum.

The report claims this put all worth on the blockchain in danger, and that the whole was over $500 million on the time of disclosure.

The determine at the moment sits at $280 million, the overwhelming majority of which is within the INJ token.

Embed: Oracle error provides to turmoil at DeFi big Aave

The bounty

Injective is a blockchain community which lists the likes of Binance, Soar, Google and Pantera as companions, claiming “institutional and government players are joining us.”

Bug bounties are a typical approach for organizations to crowdsource steady safety monitoring from specialist whitehat bounty “hunters.”

Injective’s ImmuneFi web page lists a most bounty of $500,000 for vital threats associated to its blockchain and good contracts.

The researcher claims, “a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.”

Additionally they allege that injective “ghosted” for 3 months after the repair, earlier than providing a bounty 10x decrease than the utmost. “To be clear: the $50K has not been paid either,” they stress. 

Protos has reached out to Injective for touch upon al_f4lc0n’s claims, however hadn’t obtained a response earlier than publication. This text might be up to date ought to we obtain one.

Why October Might Turn into a Turning Level for XRP
$300M Crypto Scheme Shakes Spain
Technique features $8B in market cap after IRS waiver
Europe on Alert After Vienna Crypto Homicide of Politician’s Son
$4 Billion in Crypto Choices Disappear In the present day—2026 Bets Surge
TAGGED:500MaccusesbugDisclosureghostinghackerInjectiveWhitehat
Share This Article
Facebook Email Print
Previous Article Tax deductions and credit you don't need to miss Tax deductions and credit you don't need to miss
Next Article The ‘average rent’ mirage: why we want higher numbers to grasp city economics | Fortune The ‘average rent’ mirage: why we want higher numbers to grasp city economics | Fortune
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Popular News
Not utilizing a Shares and Shares ISA? You possibly can be lacking out on a rich retirement!
Marketing

Not utilizing a Shares and Shares ISA? You possibly can be lacking out on a rich retirement!

Admin
By Admin
3 months ago
How a lot do you want in a Shares and Shares ISA to generate sufficient passive revenue for a ‘comfortable’ retirement?
Warren Buffett simply offered this inventory after a 3,890% rise! Ought to I purchase it?
Struggling Disney World rival faces alarming drawback
Democrats and Republicans Break up on Values—However Not on Bitcoin

You Might Also Like

Secret Struggle Bets? Polymarket Faces Data Laundering Fears

Secret Struggle Bets? Polymarket Faces Data Laundering Fears

2 months ago
Nvidia’s Rubin Seems to be Bullish for Bittensor and AI Crypto Financial system

Nvidia’s Rubin Seems to be Bullish for Bittensor and AI Crypto Financial system

2 months ago
This Is How XMR Value’s 20% Drop Under 0 is a Setup for Bulls

This Is How XMR Value’s 20% Drop Under $500 is a Setup for Bulls

2 months ago
Bitcoin devs cheer block reconstruction stats, ignore safety funds issues

Bitcoin devs cheer block reconstruction stats, ignore safety funds issues

6 months ago
about us

Welcome to Asolica, your reliable destination for independent news, in-depth analysis, and global updates.

  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
  • About Us
  • Contact Us
  • Privacy Policy
  • Cookie Policy
  • Disclaimer
  • Terms & Conditions

Find Us on Socials

© 2025 Asolica News Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?