Cryptocurrency [loss] $4M+

Tweet thread by Radiant Capital

2024-01-02 [vendor] Radiant Capital [chain] ethereum
Primary Source ↗
Financial Loss $4.5M (4,500,000 USD)
Blockchain(s) Ethereum

Incident Details

Radiant Capital, a cross-chain lending protocol built on the Arbitrum layer-2 network, was hacked for 1,900 ETH (~$4.5 million). The exploit relied on a flaw in the underlying code, which was forked from Compound and Aave. The original code has a known rounding issue, which makes new projects vulnerable to attack shortly after they are deployed if they are not specifically configured to avoid the issue. In this case, the attacker had observed the contract being deployed and performed the exploit only six seconds after the project was activated.Radiant Capital sent an on-chain message to the attacker, offering to negotiate a bounty.

Total loss estimated at $4,500,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Radiant Capital

Timeline

  1. 2024-01-02 Breach occurred
  2. 2024-01-02 Publicly disclosed