The attack took place on August 31 at 3:42 a.m. The attacker exploited a vulnerability to create binary options markets without authorization, using the insurance fund as collateral, and ran the scheme 299 times in a row. The initial capital of 9,110 USDT was transferred via the Peggy bridge.
In total, about $4.88 million was withdrawn, and the funds were immediately converted into 1,979.81 ETH in three separate transactions. The money did not pass through mixers or exchanges; it is still sitting in a single address.
The total amount lost by users due to the 299 withdrawals from the insurance fund remains undisclosed; we are awaiting official data from Injective.