Injective疑似因二元期权漏洞暂停约4小时,预计约490万美元被盗
PANews 9月1日消息,X平台用户Paddy-earthling披露,Injective今日因二元期权漏洞暂停运行约4小时,攻击者利用一个已停用但仍注册的预言机(Frontrunner)盗取约490万美元。该预言机的数据源早已清空,攻击者创建299个市场指向该预言机,因无法获取价格触发“无价格退款”机制,攻击者利用该机制漏洞获约2倍赔付,随后将USDC兑换为约1,980枚ETH(约490万美元),目前存放在一个未发送过任何交易的以太坊钱包中。 Paddy-earthling指出,攻击发生后,Injective官方X账号照常发布营销内容,只字未提链已暂停。
Injective halted about 4 hours over binary options bug; about $4.9 million estimated stolen
PANews on Sep 1: X user Paddy-earthling disclosed Injective halted for about four hours today after a binary options exploit in which an attacker stole about $4.9 million via a deactivated but still registered oracle (Frontrunner) whose data feed had long been empty. The attacker created 299 markets pointing at the oracle; with no prices available, a 'no-price refund' mechanism kicked in, and a flaw let the attacker claim roughly double payouts, then swap USDC for about 1,980 ETH (about $4.9 million) now sitting in an Ethereum wallet that has never sent a transaction. The user noted Injective's official X account kept posting marketing content without mentioning the chain halt.