← Radar

Incident case file

Sign in to watch

Injective Binary Options Market-ID Collision Exploit — $4.9M, Address Never Disclosed

Incident date Aug 30, 2026Last updated Sep 24, 2026

0 views

ActiveInjectiveEthereumMarket-ID hash collision / oracle refund abuseCluster: INJECTIVE-2026-08

Estimated loss

$4.9M

Affected users

1
Group joining is coming soon.

Investigation

30%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

Converted to ETH and bridged to Ethereum via CCTP, consolidated at a single address holding ~1,980 ETH (~$4.88M) that has shown no outgoing transactions as of the most recent independent check.

Linked

TODO — no source, including Chinese, French and English-language coverage, has published the complete consolidation address (only the truncated form 0x5a18...69ea is publicly available).

Chronology

1 beat
  1. On August 31, 2026, an attacker exploited a market-ID hash collision in Injective's permissionless binary options market creation system. Injective generates market_id by concatenating oracleType, ticker, quoteDenom, oracleSymbol and oracleProvider without separators or length prefixes, which allowed the attacker to create an INJ-denominated insurance fund whose identifier collided with a USDC-denominated binary options market's identifier. The attacker created 299 instant binary options markets over roughly 19 hours, each governed by a self-controlled oracle deliberately configured to never supply a price, with expiry and settlement timestamps only seconds apart. When settlement triggered the no-price refund path, the system attempted to cover the manufactured USDC deficit using the full raw balance of the colliding INJ-denominated fund, bypassing the discount normally required for residual positions and paying out roughly double the deposited amount per cycle (one documented sequence saw ~$105,000 deposited yield over $204,000 refunded). Validators halted the chain for approximately 3 hours 42 minutes (16:10 to 19:52 UTC) to contain the drain, preserving all executed trades rather than rolling back, as Cronos had done in a separate incident. The stolen funds were converted to approximately 1,980 ETH (~$4.9M) and bridged to Ethereum, where they have remained unmoved at a single address as of the most recent check. Injective's official social media accounts continued posting unrelated marketing content throughout the outage without acknowledging the incident, and no official post-mortem has been published. One report indicates the attacker is reportedly weighing an unverified whitehat settlement offer sent from an unverified smart wallet.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)