Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

CointelegraphPublicado em 2024-01-02Última atualização em 2024-01-03

Resumo

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

Leituras Relacionadas

Spicy Review|Is the "Most Emotionally Valuable" Post Here? Could STRC Be the Next LUNA?

Here is an English summary of the article (under 1500 characters): This article from the spicy commentary series "LaPing" covers three key stories in the crypto world for the week. First, during a sharp market downturn in June where BTC fell over 20%, a Reddit post on r/Cryptocurrency rallying against "Fear, Uncertainty, and Doubt (FUD)" went viral. The comment section became a hub for retail traders to share memes and encouragement, with many advocating holding (HODLing) through the volatility, embodying the "be fearful when others are greedy" mantra. Second, it examines the situation with STRG (Strategy's perpetual preferred stock), which has "de-pegged," trading around $76 vs. its $100 face value, a ~25% discount. The concern is whether Michael Saylor's company, MicroStrategy, can sustain the $1.2 billion annual dividend payment, given its ~$1.4 billion cash reserve. While analysts note STRG is fundamentally different from the catastrophic LUNA collapse—as Saylor isn't obligated to pay the dividend—risks remain. If MicroStrategy's (MSTR) common stock investors feel their capital is being prioritized for STRG dividends, it could hurt MSTR demand. Third, the article analyzes the online persona of "Chuan Mu," a trader famous for turning $500 into $1 million during the 2023 ORDI inscription boom and again with short positions in 2025. An analysis of his 1,828 tweets reveals his success stems from a top-down analytical framework, asking systemic questions like "Where will the bottleneck be in the AI supply chain?" rather than chasing individual pumps. His investments migrated from crypto-linked stocks to AI infrastructure plays like SK Hynix and Samsung. However, the piece also notes criticism that he has occasionally "pumped" assets and sold positions without notifying followers, creating a contradictory public image. The weekly recap highlights themes of community sentiment during bear markets, financial instrument risks, and the complex realities of following influential online traders.

Foresight NewsHá 2m

Spicy Review|Is the "Most Emotionally Valuable" Post Here? Could STRC Be the Next LUNA?

Foresight NewsHá 2m

Glue Finance Founder: ETH Has Entered a Phase of Non-Consensus, an Inflection Point Is Coming

"Glue Finance founder argues Ethereum's current price underperformance stems from its 'unfinished machine' status. Despite record usage and settlement value in 2026, ETH remains below its 2021 peak because the protocol's continued development creates a dependency on the Ethereum Foundation for guidance and fixes. Key issues include centralized L2 sequencers, governance-based freezes (as seen with Arbitrum), state bloat, a vulnerable public mempool, and looming quantum computing threats. This 'dependency discount' prevents ETH from accruing the 'ossification premium' that markets award to immutable, trustless systems like Bitcoin. The author, a self-described Ethereum maximalist, rejects two flawed escape paths: a 'war mode' shift towards centralization for speed (which would sacrifice Ethereum's core value), or simply replacing the EF with another governing body. The only solution is the 'Manhattan Plan' or 'Lean Ethereum': a concerted, accelerated effort to complete and then *freeze* the protocol's neutral core. This involves finalizing critical upgrades in consensus (Lean Consensus), scaling (targeting 1 trillion gas/sec), quantum resistance (leanXMSS signatures), and full ZK-provable execution. The goal is to pass the 'walk-away test'—where Ethereum could run forever, neutrally, without the EF. Success would transform Ethereum into the first programmable, quantum-resistant, immutable global settlement layer, flipping its current discount into a unique 'eternity premium' that surpasses Bitcoin's. Failure—stagnation or trading neutrality for speed—would relegate it to being a slower, less trustworthy competitor."

marsbitHá 28m

Glue Finance Founder: ETH Has Entered a Phase of Non-Consensus, an Inflection Point Is Coming

marsbitHá 28m

Glue Finance Founder: ETH Has Entered a Phase of Non-Consensus, an Inflection Point Is Approaching

Glue Finance founder argues that Ethereum's current price underperformance, despite high on-chain activity, stems from its incomplete state and lingering dependency on central stewards like the Ethereum Foundation. The core thesis is that the market is discounting ETH not for lack of use, but because the protocol remains a "machine under construction." Key unresolved issues include centralized L2 sequencers with limited escape hatches, state bloat, vulnerable public mempools, and the looming quantum computing threat. This perpetual "work-in-progress" status forces reliance on a small group of maintainers, undermining the network's promise of credible neutrality and immutability. The author, a self-described Ethereum maximalist, rejects two flawed paths: a "wartime mode" of centralizing for speed (surrendering Ethereum's unique value) or merely replacing the Foundation with another governing entity. The only solution is to complete and then "freeze" the protocol's neutral core through a focused "Manhattan Project" dubbed "Lean Ethereum." This project aims to bundle critical upgrades—consensus layer overhaul, massive scaling via ZK-proofs, quantum resistance, and statelessness—into a decisive push to finalize the base layer. Once the core rules are cryptographically solidified and beyond anyone's control (passing the "walk-away test"), Ethereum would shed its dependency discount and earn a "rigidity premium" for its credible neutrality and programmability, potentially surpassing Bitcoin's valuation. The race is between completing this hardening and the risks of protocol capture or stagnation.

链捕手Há 29m

Glue Finance Founder: ETH Has Entered a Phase of Non-Consensus, an Inflection Point Is Approaching

链捕手Há 29m

Hackers Steal Nearly $17 Million in 40 Days as 'Zombie Contracts' Become Their ATMs

According to an analysis published by ZeroDrift on June 22, 2026, attackers have stolen approximately $16.9 million over 40 days from five deprecated but still operational smart contracts across various blockchains. The primary issue is not a specific vulnerability but the incomplete decommissioning of legacy contracts. These "zombie contracts" often retain economic value, operational permissions, and callable functions, making them prime targets long after teams cease active development. The most significant loss occurred at DxSale, where an old locker contract lost about $7.3 million due to a forgotten control path becoming accessible again. Other affected projects include TrustedVolumes (~$5.87M), Raydium's legacy AMM pool (~$1.34M), Aztec Connect (~$2.28M), and Huma Finance V1 pool (~$101k). These incidents involved diverse systems—RFQ settlement, credit pools, liquidity lockers, AMMs—demonstrating the widespread nature of the risk. The analysis highlights that automated tools are lowering the cost for attackers to systematically scan for these long-tail targets, which have public code and weaker monitoring. In contrast, defensive practices for contract retirement remain underdeveloped. While the DeFi industry has mature audit processes for new deployments, it lacks strict protocols for securely sunsetting old contracts, which only become truly "retired" after all funds, permissions, authorizations, and trust assumptions are removed.

marsbitHá 1h

Hackers Steal Nearly $17 Million in 40 Days as 'Zombie Contracts' Become Their ATMs

marsbitHá 1h

Trading

Spot
活动图片