Injective Protocol Vulnerability: White Hat Hacker Disputes $50K Bounty for $500M Flaw

Injective Protocol Vulnerability: White Hat Hacker Disputes $50K Bounty for $500M Flaw

First seen 16 Mar 2026, 13:38 UTC PanewslabCryptorank 66.0

Article Content

Browse articles
ThreatCluster

A white hat hacker named f4lc0n discovered a critical vulnerability in the Injective protocol that could allow the extraction of over $500 million in digital assets. The vulnerability enables any user to wipe accounts on the blockchain without special privileges. After reporting the flaw through Immunefi, the Injective team initiated a mainnet upgrade to address the issue but remained silent for three months. Upon resuming communication, the team offered a reward of only $50,000, significantly less than the expected maximum of $500,000 for such a critical vulnerability. F4lc0n has publicly contested the bounty amount and stated that the reward has not yet been paid. He plans to dedicate 10% of future bounty revenue to raise awareness about the issue until Injective fulfills its obligation. The situation has sparked discussions on bug bounty ethics and transparency in blockchain security.

Key Points: • A critical vulnerability in Injective could allow the theft of over $500 million. • The Injective team offered only $50,000 for the vulnerability, far below expected compensation. • The white hat hacker f4lc0n plans to raise awareness until the promised bounty is paid.

Timeline

2026-03-16
f4lc0n disclosed the vulnerability on social media.
2026-03-16
Injective team initiated a mainnet upgrade vote.
2026-03-16
Injective offered a $50,000 reward for the vulnerability.