Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

Cointelegraph2024-01-02 tarihinde yayınlandı2024-01-03 tarihinde güncellendi

Özet

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

İlgili Okumalar

Airwallex's Pivot: From Dismissing Stablecoins a Year Ago to Making High-Profile Investments Today

Airwallex, a major cross-border payments fintech, has made a notable strategic shift by leading a seed round investment in Metal, a tokenized financial settlement network. This move is significant given that Airwallex founder Jack Zhang was a prominent critic of stablecoins just a year prior, arguing they failed to reduce costs for mainstream currency corridors and lacked clear utility. The investment targets Metal, a Layer-1 blockchain designed for the tokenization and settlement of assets like stocks, bonds, and stablecoins, aiming for the institutional market. Metal's team includes veterans from Ren Protocol and Meta's Diem project. For Airwallex, this partnership integrates tokenized finance into its global payments network, providing a new settlement layer. Despite his company's investment, Zhang maintains a distinction, stating his skepticism toward "cryptocurrencies" remains, while classifying regulated, asset-backed stablecoins as a separate category. This stance reflects a broader trend of traditional finance (TradFi) cautiously engaging with crypto infrastructure. Companies like Stripe, Mastercard, and major banks are similarly exploring stablecoin payments and tokenization networks, recognizing their potential in emerging markets and 24/7 settlement. The article concludes that Airwallex's investment is less a change of belief and more a strategic necessity to secure a position in the evolving landscape of digital asset settlement, where stablecoins are becoming a key interface for global finance.

marsbit35 dk önce

Airwallex's Pivot: From Dismissing Stablecoins a Year Ago to Making High-Profile Investments Today

marsbit35 dk önce

Spicy Review|Is the "Most Emotionally Valuable" Post Here? Could STRC Be the Next LUNA?

Here is an English summary of the article (under 1500 characters): This article from the spicy commentary series "LaPing" covers three key stories in the crypto world for the week. First, during a sharp market downturn in June where BTC fell over 20%, a Reddit post on r/Cryptocurrency rallying against "Fear, Uncertainty, and Doubt (FUD)" went viral. The comment section became a hub for retail traders to share memes and encouragement, with many advocating holding (HODLing) through the volatility, embodying the "be fearful when others are greedy" mantra. Second, it examines the situation with STRG (Strategy's perpetual preferred stock), which has "de-pegged," trading around $76 vs. its $100 face value, a ~25% discount. The concern is whether Michael Saylor's company, MicroStrategy, can sustain the $1.2 billion annual dividend payment, given its ~$1.4 billion cash reserve. While analysts note STRG is fundamentally different from the catastrophic LUNA collapse—as Saylor isn't obligated to pay the dividend—risks remain. If MicroStrategy's (MSTR) common stock investors feel their capital is being prioritized for STRG dividends, it could hurt MSTR demand. Third, the article analyzes the online persona of "Chuan Mu," a trader famous for turning $500 into $1 million during the 2023 ORDI inscription boom and again with short positions in 2025. An analysis of his 1,828 tweets reveals his success stems from a top-down analytical framework, asking systemic questions like "Where will the bottleneck be in the AI supply chain?" rather than chasing individual pumps. His investments migrated from crypto-linked stocks to AI infrastructure plays like SK Hynix and Samsung. However, the piece also notes criticism that he has occasionally "pumped" assets and sold positions without notifying followers, creating a contradictory public image. The weekly recap highlights themes of community sentiment during bear markets, financial instrument risks, and the complex realities of following influential online traders.

Foresight News1 saat önce

Spicy Review|Is the "Most Emotionally Valuable" Post Here? Could STRC Be the Next LUNA?

Foresight News1 saat önce

İşlemler

Spot
活动图片