$50m Hack: Radiant Capital Hit Hard In Rare Multi-Sig Wallet Attack
According to a post from Blockchain security firm Slowmist, the private keys to 3 out of 11 addresses that managed the Radiant Capital project were compromised, and this was enough to approve malicious transactions that...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
According to a post from Blockchain security firm Slowmist, the private keys to 3 out of 11 addresses that managed the Radiant Capital project were compromised, and this was enough to approve malicious transactions that involved a “transfer ownership of the LendingPoolAddressesProvider contract to a malicious contract controlled by the attacker.” This then allowed the attacker to drain Radiant Capital’s lending pools on Arbitrum and BNB Chain.
Radiant Capital acknowledged the attack a few hours after it happened. They also paused their Base and Ethereum contracts as a precaution. On October 18th, the project wrote a longer post-mortem tweet stating — “The attackers exploited multiple developers’ hardware wallets through a highly advanced malware injection.”
They continue that Radiant Capital DAO “is deeply devastated by this attack and will continue to work tirelessly with the respective agencies to identify the exploiter and recover the stolen funds as quickly as possible.” They note in the post-mortem —“The DAO has significantly tightened security on the Admin & DAO multi-sigs (other safes to follow in due course) by reducing the number of signers to 7, with a new signing threshold of 4 out of 7, ensuring that nearly 60% of signers must approve a transaction before it can be executed.”
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Brave New CoinRelated market context
Block traces COLDCARD attacker to blockchain services provider after $38M Bitcoin theft
The incident underscores the critical need for rigorous firmware testing and swift vulnerability disclosures to protect digital as...
China tightens exit rules to address tech security risks, raising fresh questions for crypto capital flows
China's new regulation could stifle tech innovation and crypto flows, impacting global markets and escalating geopolitical tension...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets
Galaxy Research says a third wave of thefts from Coldcard Bitcoin wallets has pushed observed losses to roughly 1,367 BTC across 4...
CleanCore’s $800M AI Contract Shows Dogecoin Treasury Firms Are Changing Shape
CleanCore Solutions has signed a 10-year colocation agreement with Cerebras Systems valued at $800 million, and the story is not j...