Ontology and Injective both experienced major block-production interruptions around August 31 as separate security incidents disrupted two Layer-1 networks, with an apparent exploit on Injective estimated to have extracted approximately $4.9 million. Injective stopped producing blocks for roughly three hours and 42 minutes before validators deployed an emergency patch and restored the network without rolling back previously confirmed transactions. Independent on-chain researchers attribute the disruption to an exploit involving Injective’s binary-options infrastructure and associated insurance funds.
Approximately $4.8 million to $4.9 million was reportedly extracted before the network stalled. Injective has not yet published a complete technical post-mortem confirming either the final loss or precise vulnerability, making the current reconstruction preliminary. Ontology’s halt was separate. Its developers deliberately suspended mainnet block production on August 31 after identifying a potential security concern during a routine check.
Injective Attacker Exploits Refund Mechanism
Current on-chain analysis points to Injective’s permissionless binary-options system rather than the network’s underlying consensus mechanism. The attacker reportedly created binary-options markets using a self-controlled oracle configured so that a valid settlement price would not be supplied. That forced affected markets into Injective’s no-price refund process. Researchers analyzing the transactions say weaknesses in the settlement and insurance-fund accounting then allowed the attacker to withdraw substantially more collateral than had originally been deposited. One reconstructed sequence showed approximately 105,199 USDC being deposited while more than 204,000 USDC was subsequently withdrawn.
The process was repeated across multiple transactions. The attacker reportedly bridged proceeds from Injective to Ethereum using Circle’s Cross-Chain Transfer Protocol before swapping assets into ETH. Independent estimates place the resulting proceeds near $4.9 million. Block production eventually deteriorated severely, with block times reportedly stretching toward 38 minutes before the network stopped advancing. Infrastructure provider QuickNode recorded a network-wide stall followed by an emergency software patch. Injective subsequently restarted without a blockchain rollback, meaning previously finalized transactions were not reversed.
Ontology Confirms Attack but Says Assets Are Safe
Ontology initially described its August 31 shutdown more cautiously. The project’s core development team said it had detected a potential security concern during a daily review and immediately coordinated with validators to suspend block production while an investigation was conducted. At that point, Ontology said there was no confirmed security incident and no evidence that ONT, ONG or other user assets had been compromised. Its assessment changed on September 1.
Following further investigation, Ontology confirmed that its developers had identified malicious attack activity targeting the network. The mainnet remains temporarily paused while developers remediate the vulnerability, upgrade affected network components and conduct additional testing with validators and security partners. Ontology continues to state that user assets were not affected. The team said it aims to restore normal mainnet operations within 24 hours, provided its security checks and network upgrade are completed successfully. The simultaneous disruptions highlight two very different approaches to blockchain security incidents.
Ontology sacrificed availability proactively, halting transactions before its investigation had established that an attack was underway. Injective’s network, according to current evidence, instead degraded while an attacker was already exploiting application-level financial infrastructure. That distinction is important. There is currently no evidence connecting the two incidents, despite their occurring within a similar time window. The Injective case also illustrates how application-layer vulnerabilities can threaten an entire financial blockchain without compromising its underlying consensus protocol. Injective’s base blockchain ultimately resumed without rewriting transaction history. But if the approximately $4.9 million estimate is confirmed, the incident will raise broader questions about the safeguards surrounding permissionless derivatives markets, user-controlled oracle configurations and insurance funds embedded directly within Layer-1 financial infrastructure. For Ontology, the financial impact currently appears considerably smaller: no user losses have been identified. Its more immediate cost is downtime. Until both networks publish detailed post-mortems, however, the full causes and consequences of the two incidents remain unresolved.
