Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

CointelegraphОпубліковано о 2024-01-02Востаннє оновлено о 2024-01-03

Анотація

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

Пов'язані матеріали

Websea's Third Anniversary: The Adjustments and Choices of a Mid-Sized Exchange During an Industry Shakeout Period

Websea, a mid-sized cryptocurrency exchange, celebrated its third anniversary in 2026 amid a period of industry consolidation. While the crypto landscape broadens with TradFi, RWA, and stablecoins, several established exchanges have retreated. This highlights the challenge for mid-tier platforms: growth is not automatic and depends on liquidity, compliance, security, and user retention. Websea has recently focused on strategic product adjustments. Key initiatives include enhancing risk management tools like contract insurance and copy trading, expanding its asset offerings to include TradFi CFDs (gold, silver, indices, forex), launching a Proof of Reserves (PoR) system for transparency, and engaging in regional RWA development through events like a summit in Almaty. The article analyzes these moves. Risk management products aim to improve user experience and retention, but their long-term viability hinges on clear rules and sustainable mechanisms. Offering TradFi CFDs seeks to capture user engagement during crypto market lulls, though it introduces new operational complexities. The PoR report addresses transparency concerns, but its value depends on regular updates. Regional RWA exploration offers potential access to real-world assets but faces significant hurdles in legal structuring and productization. Ultimately, Websea's three-year mark showcases a strategy to compete by broadening tradable assets, strengthening risk and transparency features, and exploring niche opportunities. The critical test will be whether these adjustments translate into sustainable trading volume, lasting user loyalty, and verifiable business growth over time.

marsbit28 хв тому

Websea's Third Anniversary: The Adjustments and Choices of a Mid-Sized Exchange During an Industry Shakeout Period

marsbit28 хв тому

Торгівля

Спот
活动图片