An attacker built a fake oracle on Injective, draining insurance funds and causing a 3‑hour halt; Ontology paused its mainnet as a precaution.

An attacker exploited a fake oracle on the Injective protocol, siphoning roughly $4.9 million from its insurance fund and forcing a three‑hour network halt.

How the Exploit Unfolded

The malicious actor deployed a counterfeit price feed that appeared legitimate to Injective’s oracle system. By feeding inflated values, the attacker triggered a series of liquidations that emptied the protocol’s insurance reserves.

Injective’s automated safeguards detected the abnormal activity and automatically paused transaction processing, limiting further loss but also suspending user activity for about three hours.

Immediate Response and Mitigation

Injective’s core team quickly isolated the compromised oracle, rolled back the affected blocks, and began a forensic audit to trace the stolen funds. The protocol also announced plans to reinforce oracle verification mechanisms and diversify price sources.

  • Conduct a comprehensive audit of all oracle integrations
  • Introduce multi‑signature approval for new price feeds
  • Implement stricter monitoring thresholds for price volatility

Ripple Effects on Ontology

In parallel, Ontology’s development team elected to pause its mainnet as a precautionary measure, citing the broader risk landscape highlighted by the Injective breach. The halt allows Ontology to review its own oracle dependencies and ensure no similar vulnerabilities exist.

Ontology’s spokesperson emphasized that the pause is a proactive step, not a sign of an active attack, and that normal operations are expected to resume once security checks are completed.

"We are closely monitoring the situation and will take all necessary actions to protect our ecosystem," the Ontology team said.

Both incidents underscore the growing importance of robust oracle design in decentralized finance, where price feeds serve as critical trust anchors for millions of dollars in assets.

EthNews coverage of Injective exploit and Ontology mainnet pause