Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

Cointelegraph发布于2024-01-02更新于2024-01-03

文章摘要

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

你可能也喜欢

7个月超15数学家6年工作量,AI写下百万行代码挑战核验超大数学证明工程

有限单群分类(CFSG)是现代数学规模最庞大的证明工程之一,涉及上百位数学家、数百篇论文和近两万页内容,远超个人复核能力。为推进AI在数学领域的应用,清华求真书院等团队提出FormaTheoria工作流:让AI从原始文献出发,自动梳理依赖关系、整合知识并构建形式化证明,最终由Lean证明助手核验。 截至2026年8月,FormaTheoria已形式化了四个关键定理(Feit–Thompson、Glauberman Z*、Brauer–Suzuki和Bender–Suzuki),生成超过99.4万行相互关联的Lean代码,查阅了15部书籍与论文共1037页。项目构建了包含数万个数学声明和百万条依赖关系的证明网络,最长依赖链达458层。 与传统人工形式化相比,AI显著提升了效率。例如,Feit–Thompson定理此前的人工形式化需约15人耗时六年完成,而FormaTheoria在七个月内不仅完成了该定理,还拓展了其他关键定理的证明。此外,系统在形式化过程中发现了文献中的不一致定义、遗漏条件、排版错误等问题,并通过自动修正或交由数学家判断的方式处理,提升了证明的可靠性。 FormaTheoria展现了AI参与系统性数学知识建构的潜力,通过人机协作模式——人类负责关键判断,AI承担搜索与推导,形式系统确保可检验性——为管理超大规模数学证明提供了新路径。

marsbit23分钟前

7个月超15数学家6年工作量,AI写下百万行代码挑战核验超大数学证明工程

marsbit23分钟前

莫斯科及多地区逮捕利用纪念钞盗取超1亿卢布犯罪团伙成员

俄罗斯内务部发言人伊琳娜·沃尔克宣布,警方在莫斯科及多个地区逮捕了八名男子,他们涉嫌通过“纪念币”骗局从多家银行窃取超过1亿卢布。 据调查,该骗局由一名莫斯科居民策划。他在自己公寓内印制外观类似俄央行5000卢布纸币的纪念币,并通过同伙将其存入银行ATM机,资金转入专门用于非法操作的“傀儡”银行卡中。 警方在接到银行安全部门报告后展开调查,在现金回收中发现了上千张此类纪念币。行动覆盖莫斯科、莫斯科州、萨马拉州以及斯塔夫罗波尔和克拉斯诺达尔边疆区,最终逮捕8名嫌疑人。犯罪分子已通过ATM存入超过2万张仿制纸币,造成银行损失超1亿卢布。调查人员查获了用于制造纪念币的设备。 莫斯科东北行政区内务局调查部门已按《俄罗斯联邦刑法典》第158条第4部分(特大盗窃罪)提起刑事诉讼,所有涉案人员均被羁押。调查仍在继续,以查明更多犯罪情节和可能的同伙。 此案显示了有组织犯罪如何结合实物伪造和数字工具(傀儡卡)从银行系统窃取资金。同时暴露了ATM机自动化现金接收的漏洞:设备能识别面额和部分防伪特征,但完全模仿5000卢布纸币物理参数可使系统误判。随着此类通过ATM的欺诈案件在俄罗斯迅速增长,如何使验钞设备有效区分纪念币与真钞,成为系统安全的关键问题。

cryptonews.ru33分钟前

莫斯科及多地区逮捕利用纪念钞盗取超1亿卢布犯罪团伙成员

cryptonews.ru33分钟前

Robinhood链再现市值过亿金狗,币股配对Meme反哺RWA

近日,Robinhood Chain上名为AI的Meme币市值一度触及1亿美元,过去一周涨幅近10倍。AI是该链上“币股配对”板块的龙头项目,其与Robinhood Chain上的英伟达股票代币NVDA配对,并建立了社区金库,将部分交易费用用于回购销毁代币。 AI的爆发得益于生态内Meme发行平台LONG的推动。LONG凭借“币股配对”的新玩法,已成为Robinhood Chain头部发射平台之一。其平台发行的Meme币日交易量在全链位居第三。 “币股配对”指发行Meme币时选择某个股票代币(如NVDA、TSLA)作为计价单位和交易对资产,而非ETH等公链代币。这使得Meme币价格同时受加密市场情绪和对应股票价格的双重影响,投资者相当于进行“双下注”。在实际交易中,用户支付的ETH会在后端兑换为股票代币,再用于兑换Meme币。 这一模式意外地促进了Robinhood Chain上RWA(现实世界资产)板块的交易。数据显示,币股配对Meme币带来的股票代币交易量约占RWA总交易量的34%,是第二大贡献来源。其中,LONG平台贡献了绝大部分交易,仅NVDA的交易量就超过9400万美元。 Robinhood CEO Vlad Tenev对此表示,Meme交易带动股票代币流动性的现象超出团队预期,他认为这种将不同资产类别组合创新的做法颇具价值。币股配对模式为股票代币在链上的应用场景提供了新的探索方向。

Odaily星球日报37分钟前

Robinhood链再现市值过亿金狗,币股配对Meme反哺RWA

Odaily星球日报37分钟前

交易

现货
活动图片