Radiant Capital Suffers $50 Million Loss in Latest Blockchain Exploit

Radiant Capital has lost over $50 million in a cyberattack, marking its second exploit this year. Security experts are investigating the breach, which involved the theft of private keys from a multi-signature wallet.

Radiant Capital, a decentralized finance (DeFi) lending protocol, has suffered a significant loss of over $50 million due to a cyberattack that exploited vulnerabilities in its blockchain contracts. This incident marks the second exploit for the platform this year, raising concerns about security in the rapidly evolving DeFi landscape.

Key Takeaways

  • Radiant Capital lost over $50 million in a cyberattack on its blockchain contracts.
  • The exploit involved the theft of private keys from a multi-signature wallet.
  • This is the second major exploit for Radiant Capital in 2024, following a $4.5 million loss in January.
  • Security experts are investigating the potential sources of the breach, including possible phishing attacks.

Overview of The Attack

On Wednesday, Radiant Capital's blockchain contracts were compromised, leading to the theft of funds from users on both the Binance Smart Chain (BSC) and Arbitrum networks. Security experts reported that the attacker gained access to three of the private keys controlling the protocol's multi-signature wallet, which consists of 11 signers. This breach allowed the hacker to upgrade the platform's smart contracts and execute unauthorized transactions.

The exploit utilized the 'transferFrom' function, enabling the attacker to drain various cryptocurrencies, including USDC, WBNB, and ETH, from user accounts. The total losses have been estimated at around $51.5 million, with significant amounts siphoned from both BSC and Arbitrum instances.

Previous Exploits

This incident is not the first for Radiant Capital. Earlier in January 2024, the protocol experienced a separate hack that resulted in a loss of $4.5 million due to a bug in its smart contracts. The repeated targeting of Radiant raises questions about the security measures in place and the overall vulnerability of DeFi platforms.

Investigating The Breach

As the investigation unfolds, security experts are exploring how the private keys were compromised. Speculations suggest that the attack may have originated from a compromised front-end, where legitimate key-holders inadvertently interacted with a malware-infected protocol. The platform has paused its markets on Base and Mainnet while collaborating with security firms like SEAL911, Hypernative, ZeroShadow, and Chainalysis to address the issue.

User Advisory

In light of the exploit, users are advised to revoke any permissions granted to Radiant Capital contracts to safeguard their funds. Security experts recommend exercising caution when interacting with DeFi platforms, especially in the wake of such significant breaches.

Conclusion

The recent exploit of Radiant Capital underscores the ongoing challenges faced by DeFi protocols in maintaining security and protecting user assets. As the industry continues to grow, the need for robust security measures and user awareness becomes increasingly critical. The situation remains fluid, and updates from Radiant Capital are anticipated as the investigation progresses.

Sources

[ newsletter ]
Stay ahead of Web3 threats—subscribe to our newsletter for the latest in blockchain security insights and updates.

Thank you! Your submission has been received!

Oops! Something went wrong. Please try again.

[ More Posts ]

Detecting Phishing in Decentralized Systems with AI
22.12.2024
[ Featured ]

Detecting Phishing in Decentralized Systems with AI

AI enhances phishing detection in decentralized systems, ensuring security with real-time monitoring and analytics.
Read article
Two Southern California Men Charged in $22 Million Cryptocurrency Fraud Scheme
21.12.2024
[ Featured ]

Two Southern California Men Charged in $22 Million Cryptocurrency Fraud Scheme

Two Southern California men, Gabriel Hay and Gavin Mayo, have been indicted for allegedly defrauding investors out of over $22 million in a cryptocurrency fraud scheme involving NFTs.
Read article
$75,000 Crypto Scam: Tinder Match Leads to Major Loss for Juniata County Man
21.12.2024
[ Featured ]

$75,000 Crypto Scam: Tinder Match Leads to Major Loss for Juniata County Man

Police in Juniata County are investigating a $75,000 crypto scam initiated through Tinder, where a man was convinced to invest in a fraudulent app.
Read article