Radiant Capital Hack
Incident Overview
Radiant Capital suffers $4.5 million loss in ETH due to flash loan attack.
On January 2, 2024, Radiant Capital, a multichain lending protocol, was attacked through a flash loan exploit, resulting in the theft of over 1,900 ETH, valued at over $4.5 million. The attacker exploited a vulnerability in the project's token quantity calculation, involving precision expansion and rounding. By controlling the precision and using rounding to expand profit margins, the attacker drained all USDC from the pool.
As of the time of writing, the stolen 1,902 ETH remains in the hacker's address without any movement.
Attacker address:
https://arbiscan.io/address/0x826d5f4d…9dde6d
Malicious transactions:
https://arbiscan.io/tx/0x1ce7e9a9…4c7c9b
https://arbiscan.io/tx/0x2af55638…d14243
https://arbiscan.io/tx/0xc5c4bbdd…77fc6d
Malicious contract:
https://arbiscan.io/address/0x39519c02…8faa8f
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Radiant Capital, these are the critical security checks that could have prevented this incident (January 2024).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Web Archive https://archive.ph/qx0Dc
Learn to Prevent the Next Radiant Capital
The Radiant Capital hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.