Radiant Capital Hack

Reported loss $58.0M
Arbitrum BNB Chain
Access Control

What happened

On October 16, 2024, attackers used malware on multiple Radiant developer devices to make Safe multisig signers approve malicious upgrade transactions while displaying benign details. The attackers took control of Radiant's LendingPoolAddressesProvider, replaced the LendingPool implementation, and drained lending markets on Arbitrum and BNB Chain.

How it happened

Malware on developer devices altered the transaction data presented to Safe multisig signers while the displayed information appeared benign. The valid signatures authorized a transfer of LendingPoolAddressesProvider ownership and a malicious LendingPool upgrade. The new implementation drained underlying market assets through Aave V2-style transfer paths and also enabled drains from wallets that had left unlimited approvals.

Reported losses range from about $50 million to $58 million. No recovery of stolen assets has been confirmed.

Protocol details

Classification Borrowing and Lending / Protocol Logic / Social Engineering
Protocol Type Lending
Implementation language Solidity
Protocol links Website @RDNTCapital

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.