Radiant Capital Hack
What happened
On October 16, 2024, attackers used malware on multiple Radiant developer devices to make Safe multisig signers approve malicious upgrade transactions while displaying benign details. The attackers took control of Radiant's LendingPoolAddressesProvider, replaced the LendingPool implementation, and drained lending markets on Arbitrum and BNB Chain.
How it happened
Malware on developer devices altered the transaction data presented to Safe multisig signers while the displayed information appeared benign. The valid signatures authorized a transfer of LendingPoolAddressesProvider ownership and a malicious LendingPool upgrade. The new implementation drained underlying market assets through Aave V2-style transfer paths and also enabled drains from wallets that had left unlimited approvals.
Reported losses range from about $50 million to $58 million. No recovery of stolen assets has been confirmed.
Protocol details
Security review history
- Solidity Finance View report
Evidence
- report @De_FiSecurity incident report x.com
- report @AnciliaInc incident report x.com
- report Report cryptopotato.com
- report Report coindesk.com
- report @AnciliaInc incident report x.com
- report Radiant Capital October 16 post-mortem community.radiant.capital
- transaction Arbiscan: Radiant malicious upgrade exploit transaction arbiscan.io
- analysis DeFiLlama defillama.com
- analysis Radiant access-control attack review hacken.io
- analysis Explained: The Radiant Capital Hack halborn.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.