A dead oracle just drained $4.88M from Injective 🫠
Not a sophisticated hack
Not a zero-day exploit
Just a deactivated price feed that someone forgot to unregister
The oracle was called Frontrunner
Deactivated months ago
Data source emptied
Still registered on-chain
Still callable by anyone
Here's how that became $4.88M:
1️⃣ Attacker spins up 299 binary options markets, all pointed at the dead oracle
2️⃣ No price comes back, so the "no-price refund" path fires
3️⃣ Refund math pays out roughly double what it should
4️⃣ Run it 299 times
USDC out, swapped into 1,979.8 ETH, parked in an Ethereum wallet that has never sent a transaction
Then Injective stopped producing blocks for 3 hours and 42 minutes
On-chain researcher Rarma clocked the halt from block 181,027,006 to 181,027,007
QuickNode's status logs confirm it too
Then an emergency patch was deployed, the chain came back online, and there is no rollback
The shortfall is apparently covered by the insurance fund
No governance vote
No post-mortem
No word on what the patch actually changed
Crazy part is that official accounts kept posting promo content the entire time🤨
And it wasn't the only chain that went dark
Ontology paused its mainnet in the same window, before it had even confirmed anything was wrong
Since then it confirmed malicious activity and is still down for an emergency upgrade
How many chains does that make that have been just switched off this past month now? 🤔
Just another day in the Wild West of Web3