BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Radiant Capital’s $50 Million Breach Reveals New Crypto Vulnerabilities

Multi-signature security compromised via hardware wallet malware

  • Radiant Capital lost approximately $50 million due to a security breach.
  • Sophisticated malware compromised three developers’ hardware wallets.
  • Attackers used legitimate-looking transactions to mask malicious activity.
  • Industry-standard procedures failed to detect the multi-signature exploit.
  • U.S. law enforcement and ZeroShadow are working to recover stolen assets.

On October 16, 2024, Radiant Capital faced a catastrophic security breach, losing nearly $50 million USD.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

This incident rocked the crypto world, as attackers infiltrated the defenses of a decentralized autonomous organization (DAO) known for its robust security measures.

The breach, which compromised three developers using hardware wallets, raises critical questions about the vulnerabilities in multi-signature setups, a previously trusted line of defense.

A Methodical Attack

According to Radiant Capital, the attackers targeted trusted contributors within the Radiant DAO, strategically planting sophisticated malware on their devices.

These developers, who were geographically dispersed, followed industry-standard operating procedures.

- Advertisement -

They used Safe{Wallet} (formerly known as Gnosis Safe) and Tenderly for transaction simulations and verifications.

However, the attack’s sophistication lay in the malware’s ability to present legitimate-looking transactions, only to execute malicious ones in the background, bypassing all manual checks.

The Illusion of Security

During a routine multi-signature emissions adjustment, the attackers exploited the normalcy of transaction failures to extract multiple compromised signatures.

This method allowed them to execute a transferOwnership action, draining funds from Radiant’s core markets on Arbitrum and Binance Smart Chain (BSC).

The breach went undetected during manual reviews and simulations, as confirmed by external security teams, SEAL911 and Hypernative.

Identifying Vulnerabilities

The breach exposed serious gaps in current DeFi security practices.

Despite multiple layers of verification, including checks on Tenderly and display of blind-signing signatures on Ledger hardware wallets, the attackers masked their malicious intent.

This attack underscores the need for immediate improvements in security protocols. Recommended strategies include developing a multi-layer signature verification system and using an independent device for transaction verification to ensure transparency and prevent similar breaches.

A Community in Crisis

The Radiant DAO is working around the clock with U.S. law enforcement and ZeroShadow to recover the stolen assets.

All users have been urged to revoke approvals on all chains. Radiant’s contributors have implemented preventative measures such as creating new cold wallet addresses and reducing the number of required signers in multi-signature setups to enhance security.

They are also using input data decoders on Etherscan to verify transaction data before signing.

A Call for Change

This breach highlights the ever-evolving challenges facing the DeFi community. As Radiant Capital rebuilds, it plans to deploy new Safes for RIZ markets and introduce timelock contracts for added protection, although these measures are not foolproof.

By distributing responsibilities across multiple roles, the DAO aims to prevent any single point of failure.

Radiant Capital’s breach reflects a crucial turning point in the crypto industry. It serves as a stark reminder that even the most trusted systems can fall prey to determined adversaries.

As the community grapples with the implications, it is clear that innovation in security measures is not just necessary but urgent.

The incident should galvanize all stakeholders in the crypto sphere to re-evaluate their defenses, ensuring that vulnerabilities are addressed before they are exploited.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GlassWorm Attack Steals Data Via Fake Chrome Extension

GlassWorm attackers now use a multi-stage framework that steals data and delivers a remote...

SHIB’s Next $10 to $1M Miracle? Doubts Arise

Shiba Inu (SHIB) saw astronomical gains after its 2020 launch, with an initial $10...

Bitmine’s MAVAN Opens Ethereum Staking to Institutions

Bitmine Immersion Technologies (BMNR) launched its Made In America Validator Network (MAVAN), extending staking...

McLaren Racing Joins Hedera Council

McLaren Racing has joined the governing Hedera Council, gaining equal voting rights on network...

ECB to set digital euro standards this summer

The European Central Bank (ECB) expects to announce standards this summer for a potential...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading