Web3 Security Firms Confirm North Korea’s Role in Radiant Capital Hack

Web3 security firms have confirmed North Korea's involvement in the $50 million hack of Radiant Capital, revealing sophisticated malware tactics and significant financial losses.

Radiant Capital has confirmed that a recent $50 million hack of its decentralized finance (DeFi) platform was orchestrated by a North Korea-aligned hacking group. The breach, which occurred in October, involved sophisticated malware distributed via Telegram, leading to significant financial losses for the platform.

Key Takeaways

  • Radiant Capital suffered a $50 million hack attributed to North Korean hackers.
  • The attack was initiated through a deceptive Telegram message.
  • Malware disguised as a PDF file was used to infiltrate the system.
  • Radiant's total value locked (TVL) has plummeted by over 97% this year.

Overview Of The Attack

The hack was first detected on October 16, 2024, prompting Radiant Capital to collaborate with several cybersecurity firms, including Mandiant, zeroShadow, Hypernative, and SEAL 911. The investigation revealed that the attack had roots dating back to September 11, 2024, when a developer received a seemingly innocuous message from an individual impersonating a former contractor.

The message included a link to a PDF file related to smart contract auditing, which was actually a malicious file named Penpie_Hacking_Analysis_Report.zip. Upon opening, this file delivered a macOS backdoor malware known as INLETDRIFT, which communicated with an external server while masquerading as a legitimate PDF document.

Evasion Tactics

Despite Radiant Capital's stringent security measures, including transaction simulations and payload verifications, the malware managed to evade detection. The attackers cleverly manipulated front-end transaction data, leading developers to unknowingly authorize malicious transactions under the impression they were legitimate. This sophisticated planning rendered the intrusion nearly undetectable during routine security checks.

Confirmation Of North Korean Involvement

In a statement released on December 9, zeroShadow corroborated Radiant Capital's findings, attributing the hack to North Korean actors with high confidence. They noted that the movements of the stolen funds were traced back to Radiant users who failed to revoke permissions, rather than the initial incident's stolen assets.

Impact On Radiant Capital

Radiant Capital, a decentralized lending and borrowing protocol utilizing LayerZero technology, has seen its total value locked (TVL) drop dramatically. According to recent figures from DefiLlama, the TVL now stands at just over $6 million, a stark contrast to the over $300 million it boasted earlier this year.

This incident is not the first security breach for Radiant Capital in 2024. Earlier in January, a vulnerability in its smart contract led to a loss of $4.5 million, further highlighting the platform's ongoing security challenges despite the overall bullish trend in the cryptocurrency market.

Conclusion

The confirmation of North Korea's involvement in the Radiant Capital hack underscores the growing sophistication of cyber threats in the decentralized finance space. As platforms continue to innovate, the need for robust security measures becomes increasingly critical to protect against such high-stakes attacks.

Sources

[ newsletter ]
Stay ahead of Web3 threats—subscribe to our newsletter for the latest in blockchain security insights and updates.

Thank you! Your submission has been received!

Oops! Something went wrong. Please try again.

[ More Posts ]

Enhancing Security in Decentralized Ecosystems: Strategies for a Safer Future
9.2.2025
[ Featured ]

Enhancing Security in Decentralized Ecosystems: Strategies for a Safer Future

Explore strategies to enhance security in decentralized ecosystems for a safer future.
Read article
Understanding Blockchain Security Architecture: Key Principles and Best Practices for Robust Protection
8.2.2025
[ Featured ]

Understanding Blockchain Security Architecture: Key Principles and Best Practices for Robust Protection

Explore blockchain security architecture principles and best practices for robust protection in digital assets.
Read article
Revolutionizing Risk Management: How Smart Contract Insurance is Shaping the Future of Coverage
7.2.2025
[ Featured ]

Revolutionizing Risk Management: How Smart Contract Insurance is Shaping the Future of Coverage

Explore how smart contract insurance is transforming risk management with blockchain technology.
Read article