Radiant Capital Hack
What happened
On January 2, 2024, an attacker targeted Radiant's newly launched native USDC market on Arbitrum. Flash-loan-funded interactions inflated the empty market's liquidity index; a rounding issue in scaled-token accounting then let the attacker withdraw more than the corresponding aToken burn. The inflated position was used to borrow WETH, creating about 1,900 ETH of bad debt.
Case & protocol details
Attack Timeline
Radiant's new native USDC market inherited an Aave V2-style accounting path that was unsafe during empty-market initialization. The attacker used flash loans to inflate the reserve liquidity index. In a later deposit and withdrawal sequence, rayDiv rounding burned too few scaled aTokens, leaving an inflated balance that could support WETH borrowing.
This created bad debt rather than a price-oracle manipulation. Radiant paused markets and later used DAO treasury funds to settle the communal bad debt.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Post-mortem medium.com
- transaction Transaction arbiscan.io
- analysis Web Archive archive.ph
- analysis MetaTrust: Radiant Protocol flash-loan attack analysis metatrust.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.