White hat hackers discovered a vulnerability in Injective that endangers $500 million in assets, receiving only a $50,000 reward which has not yet been paid
White hat hacker f4lc0n posted on the X platform revealing that he discovered a "critical" vulnerability in the Injective protocol that could lead to over $500 million in assets being directly withdrawn from the blockchain. However, the project team only offered him a $50,000 bounty, far below the planned maximum limit of $500,000 for this level of severity.
f4lc0n stated that the vulnerability allows any user to empty any account on the blockchain without special permissions. After submitting a report through Immunefi, the Injective team initiated a mainnet upgrade vote the next day to fix the vulnerability, but they were "unreachable" for the following three months.
Currently, f4lc0n has disputed the amount of the bounty and stated that the $50,000 bounty has not yet been paid. He announced that he will allocate 10% of future bug bounty earnings to continue publicizing this matter until Injective pays the compensation as per the standard.
You may also like

Insiders betting on Musk are reaping "historic returns."

Morning Report | Binance launches DYOR research tool; YZi Labs launches recruitment platform YZi Talent; Vitalik states that the Ethereum Foundation will "downsize" and reduce the amount of ETH sold

Morning News | Michael Saylor stated that this week he bought bonds instead of Bitcoin; StablR was attacked and lost about 2.8 million dollars; the U.S. Congress is pushing the Bitcoin Reserve Act again

SuperEx's Mars exploration dream: Digital currency is the key to unlocking economic exchanges in the interstellar era

Key Takeaways: Full Text of Google Chief Scientist Shanahan's Speech

Agentic Design Patterns: A book that made me rethink "What exactly is an Agent?"

The richest chairman of the Federal Reserve in 112 years has arrived: Kevin Warsh is rewriting the rules

Vitalik talks about the future of the Ethereum Foundation: a smaller, more distinctive, yet more enduring ship

New Types of Information Laundering in Prediction Markets: How Secrets Integrate into Investment Signals

Vitalik emphasized in a post that Ethereum must be "amazing," but the foundation is not the center

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

WEEX Bitcoin Pizza Day: Zero Fees, BTC Cashback & 150,000 USDT to Honor Crypto History

a16z: 7 Images to Understand How Tokenization Changes the Nature of Assets

The secret to Hyperliquid's success dismantled from the five-layer financial stack

After Futu Securities was banned, will buying stocks on-chain be the new remedy?
Why Crypto Traders Are Watching Gold and Nasdaq Again in 2026

Why have foreign exchange stablecoins never taken off?





