Radiant Capital Hack

TOTAL LOST $4.3M
Medium Arithmetic Overflow & Underflow Attacks arbitrum

What happened

On January 2, 2024, an attacker targeted Radiant's newly launched native USDC market on Arbitrum. Flash-loan-funded interactions inflated the empty market's liquidity index; a rounding issue in scaled-token accounting then let the attacker withdraw more than the corresponding aToken burn. The inflated position was used to borrow WETH, creating about 1,900 ETH of bad debt.

Case & protocol details

Classification Borrowing and Lending
Protocol Type Lending
Affected asset / contract RDNT
Official Website radiant.capital/
Protocol Twitter/X @RDNTCapital

Attack Timeline

Radiant's new native USDC market inherited an Aave V2-style accounting path that was unsafe during empty-market initialization. The attacker used flash loans to inflate the reserve liquidity index. In a later deposit and withdrawal sequence, rayDiv rounding burned too few scaled aTokens, leaving an inflated balance that could support WETH borrowing.

This created bad debt rather than a price-oracle manipulation. Radiant paused markets and later used DAO treasury funds to settle the communal bad debt.

Security review history

Bug bounty Immunefi Details

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.