Radiant Capital Exploit 2024 event
Overview
On October 16, 2024, the cross-chain lending protocol Radiant Capital lost roughly $50 million after attackers compromised its multisignature wallet, draining funds from its markets on BNB Chain and Arbitrum. The intrusion began with malware delivered to contributors through Telegram in a file disguised as a request for feedback; the malware showed legitimate transaction data in the Gnosis Safe interface while sending malicious payloads to hardware wallets for signing, defeating the protocol's 3-of-11 multisig. Cybersecurity firm Mandiant attributed the attack to the North Korea-linked AppleJeus campaign. Radiant worked with U.S. law enforcement but never recovered most of the funds and later announced it was winding down operations.
Within the DeFi Intel graph, Radiant Capital Exploit 2024 connects to 1 tracked entity, most strongly to Radiant Capital.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 1 of 1 total).
| Relation | Connected entity | Confidence |
|---|---|---|
victim_of | Radiant Capital | 85% |
Frequently asked questions
How much did Radiant Capital lose and when?
Approximately $50 million on October 16, 2024, across its BNB Chain and Arbitrum deployments.
How was the multisig defeated?
Attackers used malware delivered via Telegram in a file posing as a feedback request. It displayed legitimate transaction data in the Gnosis Safe frontend while the actual malicious transactions were routed to signers' hardware wallets, allowing the 3-of-11 multisig threshold to be met.
Who was blamed, and what happened to Radiant?
Mandiant attributed the attack to the North Korea-linked AppleJeus campaign. Radiant could not recover most of the stolen funds and subsequently announced it was winding down.
Sources
Facts on this page were verified against the following sources.