White-hat hacker f4lc0n posted on the X platform that he discovered a critical vulnerability on the Injective blockchain through the Immunefi platform. This vulnerability allows any user to directly steal funds from any account on the blockchain without special privileges, putting over $500 million in on-chain assets at risk. The hacker stated that the Injective team submitted a fix to governance voting the day after the report was submitted, but received no follow-up or technical discussion for the next three months. Injective ultimately offered a $50,000 bounty, while the maximum bounty for a critical vulnerability on the project is $500,000. The hacker stated that he has raised objections but has received no response, and the $50,000 bounty has not yet been paid.