BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Whitehat clashes with Injective over $500M bug bounty

Injective $500M bug bounty dispute erupts after critical vulnerability disclosure.

  • A researcher disclosed a critical vulnerability that put approximately $500 million at risk on the Injective blockchain.
  • The bug allowed an attacker to create a worthless token and force victim accounts to buy it, potentially draining funds.
  • The researcher claims Injective delayed response and offered a bounty significantly lower than the disclosed maximum payout.

A pseudonymous security researcher has publicly detailed a months-long dispute with the team behind the Injective blockchain over their handling of a critical bug disclosure that put substantial funds at risk. According to a report posted to a public GitHub repository, the vulnerability could have allowed “any user to directly drain any account on the chain,” potentially jeopardizing hundreds of millions of dollars. The researcher, who goes by al_f4lc0n, accused Injective of ghosting them for three months after the fix was deployed.

- Advertisement -

Consequently, the researcher alleges that after the silence, the project offered a bounty payment far below the listed maximum for critical threats. The technical report explains the flaw stemmed from faulty subaccount validation, which could let an attacker create a worthless token and a paired market, then force sell orders on victim accounts. This method could siphon funds like USDT, which could then be bridged off the chain. The researcher states that Injective later implemented a mainnet upgrade to resolve the issue, confirming its severity.

Meanwhile, the researcher’s GitHub repository titled “injective-wall-of-shame” outlines the saga, including the claim that the offered $50,000 bounty has not yet been paid. Injective, which lists partners including Binance and Google, maintains a bug bounty program on Immunefi with a maximum reward of $500,000 for critical vulnerabilities. The researcher contends their disclosure warranted a higher reward given the scale of the risk, which they estimated at over $500 million based on total value locked on the blockchain at the time.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor Signals More Bitcoin Buys, Urges Shareholder Vote

Strategy signaled another Bitcoin purchase is likely this week, continuing its multi-year accumulation strategy.The...

NGINX Under Active Attack After Patch Release

A critical heap buffer overflow vulnerability (CVE-2026-42945) in NGINX is being actively exploited in...

Micron Soars 700%; Insiders Sell $52M as AI Boom Fuels Rally

Micron stock (MU) trades near $800, a dramatic climb from a 52-week low near...

Nasdaq Bubble: 40,000 to 60,000 Predicted by 2028

A Nasdaq analyst who predicted a 2024 boom now warns the current bubble resembles...

Japanese Brokerages Develop Crypto Investment Trusts

Major Japanese brokerages including SBI Securities and Rakuten Securities are preparing to launch in-house...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading