We collect cookies to analyze our website traffic and performance; we never collect any personal data. Cookies Policy
Accept
AsolicaAsolicaAsolica
  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
Reading: Whitehat hacker accuses Injective of ghosting after $500M bug disclosure
Share
Font ResizerAa
AsolicaAsolica
Font ResizerAa
  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
Follow US
© 2025 Asolica News Network. All Rights Reserved.
Asolica > Blog > Crypto > Whitehat hacker accuses Injective of ghosting after $500M bug disclosure
Crypto

Whitehat hacker accuses Injective of ghosting after $500M bug disclosure

Admin
Last updated: March 16, 2026 1:02 pm
Admin
7 hours ago
Share
Whitehat hacker accuses Injective of ghosting after 0M bug disclosure
SHARE

Contents
  • The bug
  • The bounty

A whitehat hacker has gone public over a months-long feud with the group behind Injective over its response to a vital bug disclosure.

In response to the report, the vulnerability in query put $500 million in danger through a defective validation system.

The pseudonymous crypto safety researcher, who goes by the moniker al_f4lc0n, has accused Injective of ghosting them for 3 months, regardless of fixing the bug, and later lowballing the bounty payout.

The bug

The bounty hunter uploaded a full bug report back to a GitHub repository referred to as “injective-wall-of-shame.”

Within the repo’s readme, entitled “I Saved Injective’s $500M. They Pay Me $50K,” they clarify that the vulnerability allowed “any user to directly drain any account on the chain. No special permissions needed.”

The extra detailed technical report describes how a defective subaccount validation system allowed for an attacker to submit market orders on different customers’ behalf.

The bug was exploitable by an attacker making a nugatory token and making a spot market, pairing it with USDT. Each these actions are permissionless on Injective.

Then, by making a promote order of the faux token, the attacker may pressure sufferer accounts to purchase the nugatory token for USDT, “at the attacker’s chosen price.” The USDT may then be permissionlessly bridged off Injective, to Ethereum.

The report claims this put all worth on the blockchain in danger, and that the whole was over $500 million on the time of disclosure.

The determine at the moment sits at $280 million, the overwhelming majority of which is within the INJ token.

Embed: Oracle error provides to turmoil at DeFi big Aave

The bounty

Injective is a blockchain community which lists the likes of Binance, Soar, Google and Pantera as companions, claiming “institutional and government players are joining us.”

Bug bounties are a typical approach for organizations to crowdsource steady safety monitoring from specialist whitehat bounty “hunters.”

Injective’s ImmuneFi web page lists a most bounty of $500,000 for vital threats associated to its blockchain and good contracts.

The researcher claims, “a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.”

Additionally they allege that injective “ghosted” for 3 months after the repair, earlier than providing a bounty 10x decrease than the utmost. “To be clear: the $50K has not been paid either,” they stress. 

Protos has reached out to Injective for touch upon al_f4lc0n’s claims, however hadn’t obtained a response earlier than publication. This text might be up to date ought to we obtain one.

Can ZEC Reside As much as Arthur Hayes’ Zcash Value Goal?
Ethereum’s Vitalik Buterin Makes a New Guess on Zcash and Privateness
Trump’s ‘Very Quickly’ Crypto Invoice Meets Congressional Gridlock – BeInCrypto
Ethereum Worth Simply Bottomed Out? Right here Is Why $4,000 Is Nonetheless On
Why Bitcoin May Collapse within the Subsequent 7–10 Years
TAGGED:500MaccusesbugDisclosureghostinghackerInjectiveWhitehat
Share This Article
Facebook Email Print
Previous Article Tax deductions and credit you don't need to miss Tax deductions and credit you don't need to miss
Next Article The ‘average rent’ mirage: why we want higher numbers to grasp city economics | Fortune The ‘average rent’ mirage: why we want higher numbers to grasp city economics | Fortune
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Popular News
Ethereum Value Falls, however Sensible Cash Is Far From Leaving
Crypto

Ethereum Value Falls, however Sensible Cash Is Far From Leaving

Admin
By Admin
3 months ago
I requested ChatGPT the place the Lloyds share worth will probably be in 2030
Amazon is promoting a $100 sensible LED ground lamp with 16 million colours for $60 throughout Black Friday
Amazon is promoting a $330 Samsung Galaxy pill for $180 throughout Prime Large Deal Days
NAKA CEO after 96% decline: ‘We’ll get this over with as rapidly as attainable’

You Might Also Like

Solana Co-Founder Is Launching a New Perp DEX

Solana Co-Founder Is Launching a New Perp DEX

5 months ago
That is Why 3X Leveraged XRP ETFs May Provide Enormous Good points

That is Why 3X Leveraged XRP ETFs May Provide Enormous Good points

5 months ago
Zcash Worth Holds Bullish Construction, However One Threat Nonetheless Lingers

Zcash Worth Holds Bullish Construction, However One Threat Nonetheless Lingers

2 months ago
Why Crypto Is at Threat as Nations Dump US Treasuries

Why Crypto Is at Threat as Nations Dump US Treasuries

2 months ago
about us

Welcome to Asolica, your reliable destination for independent news, in-depth analysis, and global updates.

  • Home
  • Business
  • Crypto
  • Finance
  • Marketing
  • Startup
  • About Us
  • Contact Us
  • Privacy Policy
  • Cookie Policy
  • Disclaimer
  • Terms & Conditions

Find Us on Socials

© 2025 Asolica News Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?