Refreshed 2h ago· updates every 6h

Radiant Capital (2024) — Crypto Hack

Laundered
Oct 16, 2024·
ArbitrumBSC
Amount Stolen
$58.0M
~12,000 ETH and various tokens
Recovered
$0

Radiant Capital's multisig signers were tricked by malware into approving malicious contract upgrades, resulting in $58M stolen.

Summary

Radiant Capital's multisig signers were tricked by malware into approving malicious contract upgrades, resulting in $58M stolen.

How It Was Compromised — DeFi via Private Key Compromise

DeFiPrivate Key Compromise

Three Radiant Capital multisig signers had their hardware wallets compromised via sophisticated malware. The malware intercepted signing requests, displaying legitimate-looking transaction data on screen while actually signing a malicious contract upgrade. The upgraded contracts contained backdoors allowing the attacker to drain lending pools.

Fund Flow & Laundering Analysis

Stolen funds moved cross-chain via bridges. ETH portion deposited into Tornado Cash. Token assets converted to ETH via aggregators before mixing. Lazarus Group attributed as responsible by US government advisories. Radiant Capital partnered with Mandiant and law enforcement but no recoveries made.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.