Cryptorank Injective Protocol Vulnerability: White Hat Hacker Disputes $50K Bounty for $500M Flaw
Article Content
- •A critical vulnerability in Injective could allow the theft of over $500 million.
- •The Injective team offered only $50,000 for the vulnerability, far below expected compensation.
- •The white hat hacker f4lc0n plans to raise awareness until the promised bounty is paid.
A white hat hacker named f4lc0n discovered a critical vulnerability in the Injective protocol that could allow the extraction of over $500 million in digital assets. The vulnerability enables any user to wipe accounts on the blockchain without special privileges. After reporting the flaw through Immunefi, the Injective team initiated a mainnet upgrade to address the issue but remained silent for three months. Upon resuming communication, the team offered a reward of only $50,000, significantly less than the expected maximum of $500,000 for such a critical vulnerability. F4lc0n has publicly contested the bounty amount and stated that the reward has not yet been paid. He plans to dedicate 10% of future bounty revenue to raise awareness about the issue until Injective fulfills its obligation. The situation has sparked discussions on bug bounty ethics and transparency in blockchain security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Injective in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…