Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Radiant Capital Loses $50M to Second Blockchain Exploit This Year

Radiant Capital Loses $50M to Second Blockchain Exploit This Year

Blockchain lending protocol Radiant Capital lost more than $50 million on Wednesday as the result of an apparent cyberattack, according to security experts and blockchain data. An attacker gained control of Radiant Capital’s blockchain contracts by obtaining three of the “private keys” that control the protocol, security experts said. “Radiant Capital contracts were exploited on BSC & ARB chains with the ‘transferFrom’ function,” Web3 security firm De.Fi explained on X. The exploit allowed attackers to “drain users’ funds, namely $USDC $WBNB $ETH and others,” the firm said. Radiant is controlled by a multi-signature, or “multisig” wallet with 11 signers, De.Fi said in a separate X post. The attacker was apparently able to obtain three of these signers’ “private keys,” which was enough to upgrade the platform’s smart contracts. The Radiant platform encompasses a suite of tools allowing users to borrow, lend, and bridge cryptocurrencies across blockchains. It’s the second time this year that the protocol has been targeted in an exploit: In January, Radiant lost $4.5 million in an unrelated hack stemming from a bug in its smart contracts. It was unclear at press time how the private keys were sabotaged in Wednesday’s attack. Some members of an Ethereum security group on Telegram, the messaging app, speculated that the attack could’ve stemmed from a compromised front-end – meaning the legitimate Radiant key-holders may have accidentally interacted with a malware-laced protocol. Radiant acknowledged the exploit in a post to its official X account, but it did not provide specific details.

Full report : Attackers obtained three out of 11 private keys to drain Radiant Capital’s blockchain contracts and siphon tokens worth $50 million.