White hat hackers discovered a vulnerability in Injective that endangers $500 million in assets, receiving only a $50,000 reward which has not yet been paid

By: rootdata|2026/03/16 11:42:00
0
Share
copy

White hat hacker f4lc0n posted on the X platform revealing that he discovered a "critical" vulnerability in the Injective protocol that could lead to over $500 million in assets being directly withdrawn from the blockchain. However, the project team only offered him a $50,000 bounty, far below the planned maximum limit of $500,000 for this level of severity.

f4lc0n stated that the vulnerability allows any user to empty any account on the blockchain without special permissions. After submitting a report through Immunefi, the Injective team initiated a mainnet upgrade vote the next day to fix the vulnerability, but they were "unreachable" for the following three months.

Currently, f4lc0n has disputed the amount of the bounty and stated that the $50,000 bounty has not yet been paid. He announced that he will allocate 10% of future bug bounty earnings to continue publicizing this matter until Injective pays the compensation as per the standard.

-- Price

--

You may also like

Popular coins

Latest Crypto News

Read more