Svmuu News: White-hat hacker f4lc0n posted on X stating that he discovered a critical vulnerability on the Injective blockchain via the Immunefi platform. This vulnerability allows any user to directly steal funds from any account on the chain without requiring special permissions, putting over $500 million in on-chain assets at risk. The hacker claimed that the day after the report was submitted, the Injective team submitted a proposed fix for a governance vote, but received no follow-up or technical discussion for the subsequent three months. Ultimately, Injective offered a $50,000 bounty, despite the project’s maximum bounty cap for critical vulnerabilities being $500,000. The hacker stated that they had raised an objection but received no response, and the $50,000 bounty remains unpaid to this day.