Radiant Capital teams with US law enforcement after $50M DeFi hack

Share This Post

Radiant Capital, a leading DeFi platform, has announced an ongoing collaboration with US law enforcement and Web3 security experts to recover over $50 million stolen in a recent hack.

In a detailed report released on Oct. 18, Radiant described the breach as one of the most complex hacks ever seen in DeFi. The team also warned that similar vulnerabilities could affect other protocols.

Post-mortem report

According to the report, the attackers used sophisticated malware to compromise the hardware wallets of at least three developers.

This malware obscured the front-end of Safe{Wallet} (previously known as Gnosis Safe), making the developers believe they were signing legitimate transactions while, in reality, malicious transactions were happening in the background.

Notably, the attack coincided with Radiant’s regular emissions adjustment process to respond to shifting market conditions. Despite thorough security checks, including manual reviews and Tenderly simulations, no suspicious activity was flagged during the process.

However, what made the attack particularly alarming was its stealth. The hackers took advantage of Safe App’s common transaction resubmission feature, often triggered by network congestion or gas price fluctuations.

They mimicked typical transaction errors to gather multiple signatures undetected. Once they had the necessary signatures, they executed the “transferOwnership” function, seizing control of Radiant’s lending pools.

The exploit targeted both Binance Smart Chain (BSC) and Arbitrum networks, allowing the attackers to manipulate the “transferFrom” function within the smart contracts. This enabled them to drain funds from users who had previously granted permission to Radiant’s lending pools.

Radiant Capital’s response

As part of their immediate security overhaul, the team has generated new cold wallet addresses for each team member using a secure, uncompromised device.

Additionally, security around Radiant’s Admin and DAO multisig wallets has been tightened. The number of signers was reduced to seven, with a new rule requiring four out of seven signatures to approve any transaction. This change ensures that 60% of signers must validate any transaction before it proceeds.

Further, to protect against future attacks, all contract updates and ownership transfers will now be delayed by at least 72 hours. This delay, enforced by timelock contracts, provides both the Radiant community and its developers ample time to review any proposed changes before they take effect.

Radiant Capital also outlined measures to help safeguard other protocols from similar threats. These include adopting more stringent signature verification processes, using separate devices to check transaction data, avoiding blind signing of critical transactions, and implementing audits triggered by error messages to catch vulnerabilities early.

The post Radiant Capital teams with US law enforcement after $50M DeFi hack appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ethereum Price Crash To $2,000 Could Happen As Smaller Timeframes Turn Bearish

Ethereum’s price trajectory has taken a sharp downturn, with technical analysis showing a possible crash to $2,000 Crypto analyst SwallowAcademy pointed out on the TradingView platform that

Bybit swiftly repays 40,000 Ethereum loan as hacker launders $250 million

Bybit has returned the 40,000 Ethereum loan, valued at roughly $9998 million, obtained from Bitget following the recent $14 billion security incident Blockchain analysis platform Lookonchain reported

Investor Alert: Dubai Regulator VARA Flags Unlicensed MKAN Coin Platform

The Virtual Assets Regulatory Authority (VARA) has issued an alert regarding MKAN Coin DMCC, which advertised virtual asset activities in the United Arab Emirates (UAE) without the necessary

DeFi 2.0 and New Tools for Passive Income in Crypto

The post DeFi 20 and New Tools for Passive Income in Crypto appeared first on Coinpedia Fintech News Decentralised Finance (DeFi) has transformed the financial landscape It leverages blockchain

Bybit Spurs Major Market Slump, But $XRP, the Best Presale Coins & AI Tokens Stand Tall

The crypto market is in the dreaded red zone Major tokens took a nosedive yesterday; even $SOL, $DOGE, and $ETH have dropped by more than 10% But it’s not all downbeat: $XRP, the best presale

The SEC Opens Four Reviewing Proposals for Spot SOL ETFs – Is This the Catalyst Solana Needs to Hit $500?

The post The SEC Opens Four Reviewing Proposals for Spot SOL ETFs – Is This the Catalyst Solana Needs to Hit $500 appeared first on Coinpedia Fintech News The SEC appears open to reviewing