pwshub.com

Radiant Capital’s $50M Breach Among ‘Most Sophisticated Hacks’ in DeFi History

Decentralized finance (DeFi) project Radiant Capital has claimed that groups analyzing its breach earlier this week “believe this was one of the most sophisticated hacks ever recorded in DeFi” and that “many protocols are at risk”.

Radiant and Web3 auditor Hacken estimated the approximate scale of the theft at $50 million, and it’s thought that USDT, USDC, and ARB tokens were stolen.

Multiple pools have been fully drained, including:
- USDC
- USDT
- wbETH
- bBTC
- wBNB
- WETH
- WBTC
- ARB
- wstETH

— Hacken🇺🇦 (@hackenclub) October 16, 2024

This sum includes at least $16 million drained from a Radiant smart contract on BNB Chain, as well as funds stolen from some of Radiance’s trading pools on the Ethereum layer-2 network Arbitrum according to Hacken.

Radiant’s platform aims to provide liquidity across different blockchain protocols and allows users to deposit collateral and borrow assets.

Inside the hack

In a blog explaining the attack, Radiant claimed hackers successfully compromised at least three developers’ hardware wallets, though they were not able to say the exact number.

Radiant claims the hackers then used malware to “manipulate transaction data at the device level” and used “poisoned signatures” that looked legitimate to the signers authorizing the transaction.

The hackers allegedly used the compromised wallets to then carry out three multi-signature approvals to move crypto to wallets they controlled.

Radiant clarified that the impacted developers had all been “long-standing, trusted contributors” to its DAO.

Radiant claims the attack used a “sophisticated method” where Radiant developers, who were using popular Ethereum multisig wallet Safe{Wallet} for transaction verification, were presented with transactions that looked legitimate.

The project said hackers were able to get past multiple layers of verification, including full-stack Web3 interface Tenderly and other auditing tools.

Radiant Capital says it is working with U.S. law enforcement and Web3 cybersecurity firm ZeroShadow, to freeze the stolen assets and recover the funds.

The project said it is taking numerous steps to prevent future breaches, such as requiring that its contributors double-confirm transaction data for every transaction using analytics platform Etherscan.

In addition, contract upgrades and ownership transfers will now be subject to a minimum 72-hour delay, to give developers enough time to review and verify changes.

Though Radiance’s recent disaster may allegedly be one of the most sophisticated hacks in DeFi history, it's by no means the largest.

In May 2022, the Ronin Network, associated with the play-to-earn game Axie Infinity, suffered a $625 million loss at the hands of hackers.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source: decrypt.co

Related stories
1 month ago - Radiant Capital's new liquidity plan could significantly boost user engagement and operational efficiency, enhancing the ecosystem's stability. The post RDNT token jumps 20% following Radiant Capital’s new liquidity plan appeared first on...
3 days ago - Radiant confirmed that its lending markets were facing an "issue" Wednesday, urging users to revoke permissions to smart contracts.
5 hours ago - The decentralized finance (DeFi) platform Radiant Capital (RDNT) is working with US law enforcement to freeze stolen assets after suffering a $50 million hack earlier this week. Hackers cracked multiple developers’ hardware wallets...
Other stories
20 minutes ago - Crypto analyst Ash Crypto has alerted the crypto community that $33.14 billion is at risk if the Bitcoin price reaches $72,462. This relates to the short positions that could be liquidated if the flagship crypto hits that price target, a...
2 hours ago - As communities of the crypto space increase so does the amount of ludicrosity that comes with it, as meme coins are now starting to shine and seemingly trying to change the digital currency landscape. On the spotlight today is the meme...
2 hours ago - The US Department of Justice says it’s apprehended six men accused of stealing over $400,000 from ATMs in New York. The men allegedly used a device to infect the New York ATMs with malware, forcing them to dispense all the cash they...
3 hours ago - Opposition to Bitcoin by non-holders could influence regulatory landscapes, potentially impacting wealth distribution and economic stability. The post ECB officials urge Bitcoin latecomers, non-holders to oppose Bitcoin and advocate for...
3 hours ago - A US judge sentenced a crypto fraudster to five years in prison over charges stemming from a $20 million scheme involving a fake Coinbase website. Chirag Tomar, an Indian national, facilitated a “spoofing” con that involved setting up a...