A white hat hacker known as f4lc0n has revealed a critical vulnerability in the Injective protocol that could have allowed over $500 million in assets to be extracted from the blockchain. According to PANews, f4lc0n disclosed this issue on the X platform, stating that the project team offered him a $50,000 bounty, significantly lower than the $500,000 maximum for such a severe vulnerability.
The vulnerability reportedly enabled any user to empty any account on the blockchain without special permissions. After f4lc0n submitted a report through Immunefi, the Injective team initiated a mainnet upgrade vote the following day to address the issue. However, the team remained unresponsive for the next three months.
f4lc0n has contested the bounty amount and noted that the $50,000 reward has yet to be paid. He announced plans to allocate 10% of future bounty earnings to publicize the matter until Injective compensates him according to the standard.