Radiant Capital’s $50 Million Breach Reveals New Crypto Vulnerabilities

Multi-signature security compromised via hardware wallet malware

  • Radiant Capital lost approximately $50 million due to a security breach.
  • Sophisticated malware compromised three developers’ hardware wallets.
  • Attackers used legitimate-looking transactions to mask malicious activity.
  • Industry-standard procedures failed to detect the multi-signature exploit.
  • U.S. law enforcement and ZeroShadow are working to recover stolen assets.

On October 16, 2024, Radiant Capital faced a catastrophic security breach, losing nearly $50 million USD.

- Advertisement -

This incident rocked the crypto world, as attackers infiltrated the defenses of a decentralized autonomous organization (DAO) known for its robust security measures.

The breach, which compromised three developers using hardware wallets, raises critical questions about the vulnerabilities in multi-signature setups, a previously trusted line of defense.

A Methodical Attack

According to Radiant Capital, the attackers targeted trusted contributors within the Radiant DAO, strategically planting sophisticated malware on their devices.

These developers, who were geographically dispersed, followed industry-standard operating procedures.

They used Safe{Wallet} (formerly known as Gnosis Safe) and Tenderly for transaction simulations and verifications.

However, the attack’s sophistication lay in the malware’s ability to present legitimate-looking transactions, only to execute malicious ones in the background, bypassing all manual checks.

- Advertisement -

The Illusion of Security

During a routine multi-signature emissions adjustment, the attackers exploited the normalcy of transaction failures to extract multiple compromised signatures.

This method allowed them to execute a transferOwnership action, draining funds from Radiant’s core markets on Arbitrum and Binance Smart Chain (BSC).

The breach went undetected during manual reviews and simulations, as confirmed by external security teams, SEAL911 and Hypernative.

- Advertisement -

Identifying Vulnerabilities

The breach exposed serious gaps in current DeFi security practices.

Despite multiple layers of verification, including checks on Tenderly and display of blind-signing signatures on Ledger hardware wallets, the attackers masked their malicious intent.

This attack underscores the need for immediate improvements in security protocols. Recommended strategies include developing a multi-layer signature verification system and using an independent device for transaction verification to ensure transparency and prevent similar breaches.

A Community in Crisis

The Radiant DAO is working around the clock with U.S. law enforcement and ZeroShadow to recover the stolen assets.

All users have been urged to revoke approvals on all chains. Radiant’s contributors have implemented preventative measures such as creating new cold wallet addresses and reducing the number of required signers in multi-signature setups to enhance security.

They are also using input data decoders on Etherscan to verify transaction data before signing.

A Call for Change

This breach highlights the ever-evolving challenges facing the DeFi community. As Radiant Capital rebuilds, it plans to deploy new Safes for RIZ markets and introduce timelock contracts for added protection, although these measures are not foolproof.

By distributing responsibilities across multiple roles, the DAO aims to prevent any single point of failure.

Radiant Capital’s breach reflects a crucial turning point in the crypto industry. It serves as a stark reminder that even the most trusted systems can fall prey to determined adversaries.

As the community grapples with the implications, it is clear that innovation in security measures is not just necessary but urgent.

The incident should galvanize all stakeholders in the crypto sphere to re-evaluate their defenses, ensuring that vulnerabilities are addressed before they are exploited.

Previous Articles:

- Advertisement -

Latest

Gold-Backed Cryptocurrencies Surge as Investors Seek Digital Safe Haven

Gold-backed cryptocurrencies like Paxos Gold (PAXG) and Tether Gold (XAUT) have surged over 24% year-to-date to all-time highs above $3,300.While tokenized gold has thrived...

Mantra (OM) token plummets 90% in 24 hours, wipes out $6B market cap

Mantra (OM) token has crashed over 90% in 24 hours, plummeting from $6.3 to under $0.50, wiping out most of its $6 billion market...

Crypto Gaming Tokens Plummet, Vanish from Top 100 as Market Struggles

Gaming tokens have disappeared from the top 100 cryptocurrency rankings by market cap despite having six representatives a year ago.Eve Frontier launched a 10-day...

Trump to impose new semiconductor tariffs on electronics within months

Commerce Secretary Howard Lutnick clarified that recent tariff exemptions for consumer electronics are only temporary.New semiconductor-focused tariffs are expected within "a month or two"...

AI Revolution: Emotional Agents Could Solve Web3 User Experience Crisis

AI agents with emotional capabilities could make Web3 tools more accessible by providing personalized guidance to new users.The steep learning curve of Web3 applications...

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...