خبری درباره‌ی Ontology (ONT)

Injective Exploit Drains $4.9M as Ontology Halts Mainnet

ETHNews.com ۱۵ روز پیش خلاصه‌ی فارسی · ۴۳۸ کلمه
Injective Exploit Drains $4.9M as Ontology Halts Mainnet

An attacker built a fake oracle on Injective and drained insurance funds through its refund path. The chain seized under the attack’s own load before validators stopped it. Ontology stopped its own chain as a precaution and reported no loss of user assets. Korean exchanges are reported to have suspended ONT transfers during the pause. Two Layer-1 networks stopped producing blocks within the same window on Aug. 31, and the coincidence was enough for most coverage to treat them as one story. They were not. Injective, the finance-oriented chain incubated by Binance, went dark for roughly 3 hours and 42 minutes while an attacker pulled value out of its binary options module, taking roughly $4.9 million before the chain seized. Ontology, an identity-focused public blockchain, stopped its own mainnet at block height 20,770,893 after its development team flagged a potential security concern during a daily check, and lost nothing at all. Injective did not stop itself. It buckled under the attack until validators had no choice. Ontology stopped itself on purpose, before anyone had taken anything. Halted under load Injective (INJ) Downtime~3 h 42 min Funds lost~$4.9M from insurance funds RestartAfter block 181,027,005 RollbackNone Exchange actionNo freeze reported Preventive halt Ontology (ONT) Downtime~5 h 06 min Funds lostNone Paused atBlock 20,770,893 RollbackNot applicable Exchange actionBithumb, Upbit reported suspensions The attacker built the oracle, named it, and pointed it at nothing Independent researcher Paddy-earthling, who discloses holding INJ, reconstructed the attack from the chain’s own transaction record and published it hours after the halt. Injective has issued no technical post-mortem of its own, so the account below rests on that analysis rather than on anything the team has confirmed. Frontrunner was not abandoned infrastructure that someone forgot to remove. The attacker created it. Using MsgInstantBinaryOptionsMarketLaunch, they spun up a binary options market with themselves as admin and attached a self-run oracle they named Frontrunner, whose symbol was NO_PRICE_FOR_REFUND_P44_USDC. Expiration and settlement timestamps sat roughly ten seconds apart, fees were set at 1e-6, and notional was uncapped. Every parameter pointed in one direction: a market built to settle instantly into the no-price refund path and nowhere else. The rest was mechanical. The attacker created an insurance fund, deposited USDC, then bought and sold both sides of the market from their own subaccounts at price 0.10 and quantity 1400. No counterparty existed at any point. In the roughly thirty-minute window the public indexer returned, deposits of 105,199 USDC produced withdrawals of 204,699 USDC. Twice out for once in, repeated in single atomic transactions from 14:59 UTC, roughly seven cycles before the chain stopped. What ended the attack was not a defence.

عنوان اصلی (انگلیسی): Injective Exploit Drains $4.9M as Ontology Halts Mainnet

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Ontology

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.