• bitcoinBitcoin (BTC) $ 89,645.00
  • ethereumEthereum (ETH) $ 3,174.70
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.00
  • bnbBNB (BNB) $ 863.62
  • usd-coinUSDC (USDC) $ 0.999763
  • solanaWrapped SOL (SOL) $ 129.90
  • staked-etherLido Staked Ether (STETH) $ 3,172.42
  • tronTRON (TRX) $ 0.278218
  • dogecoinDogecoin (DOGE) $ 0.137774
  • cardanoCardano (ADA) $ 0.430719
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • whitebitWhiteBIT Coin (WBT) $ 61.10
  • wrapped-stethWrapped stETH (WSTETH) $ 3,877.68
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,446.04
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 89,275.00
  • bitcoin-cashBitcoin Cash (BCH) $ 554.10
  • usdsUSDS (USDS) $ 0.999481
  • chainlinkChainlink (LINK) $ 13.48
  • wrapped-eethWrapped eETH (WEETH) $ 3,438.51
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.49
  • wethWETH (WETH) $ 3,175.15
  • stellarStellar (XLM) $ 0.240674
  • hyperliquidHyperliquid (HYPE) $ 28.32
  • moneroMonero (XMR) $ 402.35
  • ethena-usdeEthena USDe (USDE) $ 0.999324
  • zcashZcash (ZEC) $ 399.14
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 89,547.00
  • litecoinLitecoin (LTC) $ 80.51
  • suiSui (SUI) $ 1.54
  • avalanche-2Avalanche (AVAX) $ 13.31
  • hedera-hashgraphHedera (HBAR) $ 0.130025
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • usdt0USDT0 (USDT0) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.998904
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.146744
  • the-open-networkToncoin (TON) $ 1.60
  • paypal-usdPayPal USD (PYUSD) $ 0.999719
  • crypto-com-chainCronos (CRO) $ 0.100495
  • mantleMantle (MNT) $ 1.12
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • polkadotPolkadot (DOT) $ 2.06
  • uniswapUniswap (UNI) $ 5.32
  • aaveAave (AAVE) $ 188.59
  • usd1-wlfiUSD1 (USD1) $ 0.999280
  • bittensorBittensor (TAO) $ 280.85
  • canton-networkCanton (CC) $ 0.073292
  • rainRain (RAIN) $ 0.007602
  • bitget-tokenBitget Token (BGB) $ 3.58
  • memecoreMemeCore (M) $ 1.44
  • okbOKB (OKB) $ 113.21
  • falcon-financeFalcon USD (USDF) $ 0.999223
  • tether-goldTether Gold (XAUT) $ 4,221.29
  • nearNEAR Protocol (NEAR) $ 1.67
  • ethereum-classicEthereum Classic (ETC) $ 13.03
  • aster-2Aster (ASTER) $ 0.919922
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,175.64
  • ethenaEthena (ENA) $ 0.248903
  • pepePepe (PEPE) $ 0.000004
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 162.16
  • internet-computerInternet Computer (ICP) $ 3.32
  • pi-networkPi Network (PI) $ 0.207464
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.61
  • pump-funPump.fun (PUMP) $ 0.002743
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.465687
  • hash-2Provenance Blockchain (HASH) $ 0.027914
  • worldcoin-wldWorldcoin (WLD) $ 0.584490
  • pax-goldPAX Gold (PAXG) $ 4,219.31
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,183.39
  • global-dollarGlobal Dollar (USDG) $ 0.999755
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • kucoin-sharesKuCoin (KCS) $ 10.42
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,645.91
  • bfusdBFUSD (BFUSD) $ 0.999226
  • ripple-usdRipple USD (RLUSD) $ 0.999723
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999871
  • aptosAptos (APT) $ 1.70
  • kaspaKaspa (KAS) $ 0.047179
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.118428
  • skySky (SKY) $ 0.053958
  • quant-networkQuant (QNT) $ 84.15
  • gatechain-tokenGate (GT) $ 10.33
  • wbnbWrapped BNB (WBNB) $ 863.62
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,364.82
  • arbitrumArbitrum (ARB) $ 0.204629
  • algorandAlgorand (ALGO) $ 0.129677
  • binance-staked-solBinance Staked SOL (BNSOL) $ 141.16
  • official-trumpOfficial Trump (TRUMP) $ 5.63
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,440.77
  • cosmosCosmos Hub (ATOM) $ 2.17
  • ignition-fbtcFunction FBTC (FBTC) $ 89,255.00
  • vechainVeChain (VET) $ 0.011712
  • flare-networksFlare (FLR) $ 0.012425
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 89,783.00
  • filecoinFilecoin (FIL) $ 1.38
  • midnight-3Midnight (NIGHT) $ 0.059998
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,604.00
  • nexoNEXO (NEXO) $ 0.972011
  • xdce-crowd-saleXDC Network (XDC) $ 0.049047
  • sei-networkSei (SEI) $ 0.136545
  • usdtbUSDtb (USDTB) $ 1.00
  • render-tokenRender (RENDER) $ 1.57
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.92
  • ousgOUSG (OUSG) $ 113.59
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 28.53
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999801
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.25
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998303
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,441.31
  • bonkBonk (BONK) $ 0.000009
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,385.28
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 89,320.00
  • wrapped-flareWrapped Flare (WFLR) $ 0.012432
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010999
  • clbtcclBTC (CLBTC) $ 89,752.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999709
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • jupiter-exchange-solanaJupiter (JUP) $ 0.215380
  • story-2Story (IP) $ 1.98
  • usdaiUSDai (USDAI) $ 1.00
  • ultimaUltima (ULTIMA) $ 6,474.13
  • morphoMorpho (MORPHO) $ 1.18
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999958
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,282.39
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 150.13
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.233442
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,172.20
  • beldexBeldex (BDX) $ 0.087133
  • optimismOptimism (OP) $ 0.305996
  • dashDash (DASH) $ 45.82
  • aerodrome-financeAerodrome Finance (AERO) $ 0.614300
  • curve-dao-tokenCurve DAO (CRV) $ 0.388069
  • spx6900SPX6900 (SPX) $ 0.591651
  • usual-usdUsual USD (USD0) $ 0.997695
  • tbtctBTC (TBTC) $ 89,138.00
  • injective-protocolInjective (INJ) $ 5.36
  • blockstackStacks (STX) $ 0.293022
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.800920
  • bridged-wrapped-ether-pundi-aifx-omnilayerBridged Wrapped Ether (Pundi AIFX Omnilayer) (WETH) $ 35,382,014.00
  • myx-financeMYX Finance (MYX) $ 2.73
  • lido-daoLido DAO (LDO) $ 0.582948
  • tezosTezos (XTZ) $ 0.486536
  • gtethGTETH (GTETH) $ 3,175.85
  • starknetStarknet (STRK) $ 0.103969
  • telcoinTelcoin (TEL) $ 0.005206
  • true-usdTrueUSD (TUSD) $ 0.997758
  • celestiaCelestia (TIA) $ 0.575883
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,174.94
  • ether-fiEther.fi (ETHFI) $ 0.796349
  • usddUSDD (USDD) $ 1.00
  • stader-ethxStader ETHx (ETHX) $ 3,418.12
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • the-graphThe Graph (GRT) $ 0.044030
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,493.58
  • msolMarinade Staked SOL (MSOL) $ 174.66
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.225295
  • flokiFLOKI (FLOKI) $ 0.000047
  • ghoGHO (GHO) $ 0.999791
  • doublezeroDoubleZero (2Z) $ 0.126178
  • kaiaKaia (KAIA) $ 0.073834
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.997912
  • swethSwell Ethereum (SWETH) $ 3,475.92
  • newton-projectAB (AB) $ 0.004678
  • iotaIOTA (IOTA) $ 0.100060
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.84
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.973114
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,534.47
  • usdbUSDB (USDB) $ 0.986616
  • bitcoin-svBitcoin SV (BSV) $ 19.86
  • sbtc-2sBTC (SBTC) $ 90,104.00
  • sun-tokenSun Token (SUN) $ 0.020426
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • justJUST (JST) $ 0.038139
  • pyth-networkPyth Network (PYTH) $ 0.065105
  • dogwifcoindogwifhat (WIF) $ 0.373338
  • sad-coinSad Coin (SAD) $ 0.368107
  • pendlePendle (PENDLE) $ 2.26
  • olympusOlympus (OHM) $ 22.68
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 89,510.00
  • conflux-tokenConflux (CFX) $ 0.071338
  • basic-attention-tokenBasic Attention (BAT) $ 0.243716
  • apenftAINFT (NFT) $ 0.00000036
  • merlin-chainMerlin Chain (MERL) $ 0.341999
  • the-sandboxThe Sandbox (SAND) $ 0.136658
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.137938
  • decredDecred (DCR) $ 20.39
  • fartcoinFartcoin (FARTCOIN) $ 0.346456
  • sonic-3Sonic (S) $ 0.090823
  • heliumHelium (HNT) $ 1.81
  • flowFlow (FLOW) $ 0.208061

Radiant Capital Hack: How Hackers Used a PDF to Steal $50 Million

0 93

Radiant Capital Hack: How Hackers Used a PDF to Steal $50 Million

The $50 million hack sent shockwaves across the defi community with funds authorized to different projects completely drained.

$50 Million Hack a Stark Warning for the Defi Industry

The complexity and precision of a recent attack on Radiant Capital, a decentralized cross-chain lending protocol built on Layerzero has exposed another layer of vulnerability, even in well-secured defi projects.

On Oct. 16, Radiant Capital suffered a breach that resulted in the theft of approximately $50 million with security experts and notable developers, such as @bantg expressing concerns about the sophistication of the attack. As @bantg noted, “this level of attack is really scary. To my knowledge, the compromised signers have followed the best practices.”

A recent incident report by Radiant Capital along with an X thread by OneKeyHQ showed a step-by-step breakdown of the hack with the report strongly linking the hack with North Korean hackers.

The attack began on Sept. 11, when a Radiant Capital developer received a Telegram message from someone impersonating a trusted former contractor. According to the message, the contractor was looking for a new job opportunity in smart contract audits. It requested comments on the contractor’s work and provided a link to a compressed PDF detailing their next assignment. The hackers even mimicked the contractor’s legitimate website to add credibility.

The zip file contained a disguised executable named INLETDRIFT. Upon opening, it installed malware on the developer’s macOS device, granting attackers access to the developer’s system. The malware was designed to communicate with a hacker-controlled server.

Tragically, the compromised file was shared with other team members for feedback, further spreading the malware. The attackers used their access to execute a man-in-the-middle (MITM) attack. While Radiant’s team relied on Gnosis Safe multisig wallets for security, the malware intercepted and manipulated transaction data. On developers’ screens, transactions appeared legitimate, but the hackers replaced them with malicious instructions targeting the ownership of lending pool contracts.

By exploiting a blind signing vulnerability in Ledger wallets, the attackers convinced developers to authorize a transfer ownership() call, giving them control of Radiant’s funds. In under three minutes, the hackers drained the funds, removed backdoors, and erased traces of their activities, leaving investigators with minimal evidence.

This attack highlighted the increasing sophistication of cyber threats such as the DMM bitcoin breach that led to the shutdown of the Japanese crypto exchange along with key learnings. One of such is that teams must shift to online collaboration tools to reduce malware risks. Downloading unverified files especially from external sources should be completely avoided.

Front-end transaction verification is crucial but vulnerable to spoofing. Projects should consider advanced verification tools and supply chain monitoring to detect tampering. Also, hardware wallets often lack detailed transaction summaries, increasing risk. Enhanced support for multi-sig transactions could mitigate this issue.

Strengthening asset governance with timelocks and governance frameworks can also contribute to delaying critical fund transfers, allowing teams to identify and respond to anomalies before assets are lost.

The Radiant Capital hack is a stark reminder of the vulnerabilities that persist even in projects adhering to best practices. As the defi ecosystem grows, so does the ingenuity of attackers. Industry-wide vigilance, stronger security protocols, and robust asset governance are essential to prevent such incidents in the future.

The Radiant DAO continues to support Mandiant in its investigation along with cooperation from Zeroshadow and U.S. law authorities to freeze stolen assets. Radiant has also expressed its desire to share lessons gained to help the entire industry raise security standards.

Source

Leave A Reply

Your email address will not be published.