Connect with us
DAPA Banner

Crypto World

Whitehat hacker accuses Injective of ghosting after $500M bug disclosure

Published

on

Whitehat hacker accuses Injective of ghosting after $500M bug disclosure

A whitehat hacker has gone public over a months-long feud with the team behind Injective over its response to a critical bug disclosure.

According to the report, the vulnerability in question put $500 million at risk via a faulty validation system.

The pseudonymous crypto security researcher, who goes by the moniker al_f4lc0n, has accused Injective of ghosting them for three months, despite fixing the bug, and later lowballing the bounty payout.

Read more: Ethereum address poisoning spike, ‘wallets aren’t ready’ says researcher

Advertisement

The bug

The bounty hunter uploaded a full bug report to a GitHub repository called “injective-wall-of-shame.”

In the repo’s readme, entitled “I Saved Injective’s $500M. They Pay Me $50K,” they explain that the vulnerability allowed “any user to directly drain any account on the chain. No special permissions needed.”

The more detailed technical report describes how a faulty subaccount validation system allowed for an attacker to submit market orders on other users’ behalf.

The bug was exploitable by an attacker creating a worthless token and creating a spot market, pairing it with USDT. Both these actions are permissionless on Injective.

Advertisement

Then, by creating a sell order of the fake token, the attacker could force victim accounts to buy the worthless token for USDT, “at the attacker’s chosen price.” The USDT could then be permissionlessly bridged off Injective, to Ethereum.

The report claims this put all value on the blockchain at risk, and that the total was over $500 million at the time of disclosure.

The figure currently sits at $280 million, the vast majority of which is in the INJ token.

Embed: Oracle error adds to turmoil at DeFi giant Aave

Advertisement

The bounty

Injective is a blockchain network which lists the likes of Binance, Jump, Google and Pantera as partners, claiming “institutional and government players are joining us.”

Bug bounties are a common way for organizations to crowdsource continuous security monitoring from specialist whitehat bounty “hunters.”

Injective’s ImmuneFi page lists a maximum bounty of $500,000 for critical threats related to its blockchain and smart contracts.

The researcher claims, “a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.”

Advertisement

They also allege that injective “ghosted” for three months after the fix, before offering a bounty 10x lower than the maximum. “To be clear: the $50K has not been paid either,” they stress. 

Protos has reached out to Injective for comment on al_f4lc0n’s claims, but hadn’t received a response before publication. This article will be updated should we receive one.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

Advertisement

Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto World

South Korean regulators fine Bithumb $24.5M after uncovering violations

Published

on

South Korean regulators fine Bithumb $24.5M after uncovering violations

Crypto exchange Bithumb will have to pay a fine of 36.8 billion won, about $24.5 million, after it was found to be in violation of South Korea’s Anti-Money Laundering rules.

Summary

  • South Korean regulators fined Bithumb 36.8 billion won, about $24.5 million, after identifying about 6.65 million AML-related violations during an inspection of the exchange’s compliance controls.
  • Authorities said Bithumb processed 45,772 crypto transfers linked to 18 unregistered overseas virtual asset service providers.
  • The exchange will face a six-month ban on external crypto transfers for new users from March 27 to Sept. 26.

According to a local media report, South Korea’s Financial Intelligence Unit under the Financial Services Commission identified about 6.65 million violations during an AML inspection where the exchange failed to properly carry out customer identity verification, transaction monitoring, and record-keeping requirements. 

Bithumb facilitated 45,772 crypto transfers involving 18 unregistered overseas virtual asset service providers in violation of the country’s AML framework.

Advertisement

Regulators decided on the penalties following a sanctions deliberation committee meeting that reviewed the exchange’s compliance with the Act on Reporting and Use of Specific Financial Transaction Information.

Bithumb has also been banned from processing external crypto transfers for new customers for six months, from March 27 to Sep. 26.

Existing customers, however, will be able to continue trading and using external transfers, while new customers can still buy or sell crypto and deposit or withdraw Korean won through the platform.

Advertisement

The penalties follow repeated warnings from the Financial Intelligence Unit, which had been urging the exchange to suspend all activity involving unregistered overseas crypto firms. Bithumb reportedly failed to implement the necessary blocking measures despite those instructions.

The latest penalty marks the largest fine ever imposed on a South Korean crypto exchange among several platforms that regulators have sanctioned for AML violations.

Last year, Upbit, one of South Korea’s largest crypto exchanges, received a three-month restriction on crypto deposits and withdrawals for new users over dealings with unregistered VASPs, alongside a 35.2 billion won penalty.

Bithumb is also navigating another probe by the Financial Supervisory Service over its operational mistake in which it accidentally credited users with an enormous amount of Bitcoin.

Advertisement

On Feb. 6, the exchange inadvertently distributed 620,000 Bitcoin worth roughly $40 billion to $44 billion at the time after an employee mistakenly entered payout amounts in BTC instead of Korean won during a promotional event.

FSS Governor Lee Chan Jin said regulators would look into how an exchange with far fewer actual reserves was able to record and distribute such large phantom Bitcoin balances within minutes, raising questions about internal controls and electronic ledger systems at the platform.

Source link

Advertisement
Continue Reading

Crypto World

Ethereum (ETH) price jumps 8.8%, leading index higher

Published

on

9am CoinDesk 20 Update for 2026-03-16: vertical

CoinDesk Indices presents its daily market update, highlighting the performance of leaders and laggards in the CoinDesk 20 Index.

The CoinDesk 20 is currently trading at 2140.46, up 5.1% (+104.17) since 4 p.m. ET on Friday.

All 20 assets are trading higher.

9am CoinDesk 20 Update for 2026-03-16: vertical

Leaders: ETH (+8.8%) and DOT (+8.5%).

Laggards: UNI (+0.9%) and BCH (+2.5%).

Advertisement

The CoinDesk 20 is a broad-based index traded on multiple platforms in several regions globally.

Source link

Continue Reading

Crypto World

3 Signs That $2,800 Is the Next Logical Target for Ethereum Bulls

Published

on

3 Signs That $2,800 Is the Next Logical Target for Ethereum Bulls

Ether (ETH) bulls are eyeing a move back toward $2,800 in March, with at least three indicators showing ETH price potential to rise higher.

Key takeaways:

  • Ether’s price jumped by over 9% toward $2,280 on Monday.

  • Multiple indicators, including a symmetrical triangle, hint at an extended price rally toward $2,800.

Ether invalidates a bearish chart pattern

On Sunday, Ether’s price action invalidated what initially appeared to be a bear pennant on the daily chart.

Related: Ethereum Foundation sells $10.2M worth of ETH to BitMine in OTC deal

Advertisement

The ETH/USD pair pierced through the pennant’s upper trend line at $2,100, jumping 9.8% to a six-week high of $2,287 on Monday. Its breakout came alongside a rise in trading volume, implying stronger conviction behind the rally.

ETH/USD daily chart. Source: Cointelegraph/TradingView

The price also reclaimed two key support lines in the name of the 20-day exponential moving average (EMA, red line) and the 50-day EMA (yellow line) at $2,072 and $2,210, respectively.

That simultaneously increased the odds of a symmetrical-triangle bullish reversal.

A symmetrical triangle forms when price makes lower highs and higher lows, compressing into a tightening range. It resolves when the price breaks either of the trendlines and moves by as much as the pattern’s maximum height.

ETH/USD daily chart. Source: Cointelegraph/TradingView

In Ether’s case, the measured move above the upper trend line points to about $2,850, 26% above the current price. The level aligns with the 200-day EMA (the purple line), as shown in the chart above.

Ether’s next hurdle is the 100-day EMA (blue) near $2,500. 

Advertisement

As Cointelegraph reported, a rejection there would weaken the breakout and raise the odds of a pullback.

Onchain data caps Ether’s upside at $2,800

ETH has been oscillating within a wide range defined by the realized price at $2,350 on the upside and on the downside at the lowest MVRV band of $1,650.

The chart below shows that the recent rebound off the lowest MVRV band mirrors the market structure observed in Q2 2022, where the price rallied past the realized price before being rejected by the first MVRV band just above. 

ETH: MVRV Extreme Deviation Pricing Bands. Source: Glassnode

This similarity reinforces the outlook that the current recovery attempt could be stopped around $2,650, where the first MVRV band sits above the realized price.

Glassnode’s Entity-Adjusted UTXO Realized Price Distribution (URPD), showing at which prices the current set of ETH UTXOs were created, also revealed a dense supply zone at $2,770-$2,880 that has been gradually maturing into the long-term holder cohort. This is where investors acquired more than 7.9 million ETH.

Advertisement

This unresolved supply overhang remains a persistent source of sell pressure, likely to cap attempts around the $2,800 level. 

ETH: Entity-Adjusted URPD. Source: Glassnode

Meanwhile, ETH’s cost-basis distribution heatmap shows a heavy accumulation near $2,800, where more than 3 million ETH were previously purchased, suggesting a potential pathway toward this level in the short term.

Polymarket’s odds of $2,800 ETH price in March rise

Polymarket, a crypto-based prediction market where users trade contracts on real-world outcomes, is showing a clear bullish shift for Ether in March.

Traders now assign 13% odds that ETH reaches $2,800 in March, a 10% increase over the last 24 hours. The $2,600 and $2,400 targets carry even stronger convictions at 32% and 69%, respectively.

ETH price targets for March. Source: Polymarket

At the same time, the odds of the ETH price reaching $1,800 and $1,600 in March are priced lower than before, suggesting the crowd is trimming downside expectations.