Whitehat Says Injective Chain Bug Put Over $500 Million at Risk, Criticizes Unpaid $50,000 Bounty Offer

Whitehat hacker f4lc0n said on X that he identified a critical vulnerability on the Injective chain through the Immunefi platform that could have enabled any user without special permissions to drain funds from any onchain account, putting more than $500 million in onchain assets at risk, Odaily Planet Daily reports. The Injective team submitted a governance fix the day after he reported the issue, but there was no followup communication or technical discussion for the next three months, f4lc0n said. He added that Injective ultimately proposed a $50,000 bounty even though the project lists a maximum reward of $5 million for critical vulnerabilities, and said he objected to the amount but did not receive a response and has still not been paid the $50,000.