Whitehat f4lc0n Reports $500M Injective Vulnerability, Disputes $50K Bounty Offer

Whitehat hacker f4lc0n said he identified a critical bug in the Injective protocol that could have allowed any user to withdraw more than $500 million in onchain assets without special permissions, ChainCatcher reports. The vulnerability effectively enabled any onchain account to be drained and was reported through Immunefi, after which the Injective team initiated a mainnet upgrade vote the next day to address the issue but remained unresponsive for three months. Injective offered a $50,000 bug bounty, which f4lc0n said falls far below the $500,000 maximum payout described for critical-level issues in the project's program and has not yet been paid. He added that he plans to donate 10% of all future vulnerability rewards to publicly draw attention to the case until Injective issues the standard reward.