Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

Cointelegraph发布于2024-01-02更新于2024-01-03

文章摘要

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

你可能也喜欢

拉美稳定币的兴起,本质上不是“加密技术的胜利”

本文探讨了拉美稳定币兴起的本质,并非加密技术的胜利,而是源于该地区深厚、迫切的跨境资金流动需求。文章以墨西哥华人餐馆老板黄先生的家族汇款史为引,指出其背后是绵延数百年的“银信”传统——一种依靠熟人社会网络与信用约束完成的跨境资金转移。 拉美地区普遍存在类似需求,大量家庭依赖海外汇款维持生计,形成了巨大的汇款市场。稳定币在此地的流行,并非人们青睐区块链技术,而是因其恰好解决了传统跨境汇款中的痛点:银行渠道慢且贵,传统汇款公司费用高,本地货币波动剧烈。在阿根廷、委内瑞拉等国,稳定币被当作“数字美元”用于保值与日常交易;在巴西、墨西哥等国,则更多嵌入跨境汇款与结算环节。 文章强调,稳定币的核心价值在于其高效的“中间清算层”,但真正的挑战在于“两头”:如何接入发送方的资金来源(如美国工资),以及如何无缝对接接收方的本地支付网络(如巴西Pix、墨西哥SPEI)。成功的服务需将稳定币技术隐藏于后台,让用户只感知到“钱快速到账”。 最后,作者指出监管机构关注的是稳定币可能形成的平行外汇体系及其风险。因此,稳定币在拉美的未来,在于成长为合规、高效的新一代汇款基础设施,无缝连接全球资金与本地生活,而这本质上是古老“银信”需求的现代表达。

marsbit51分钟前

拉美稳定币的兴起,本质上不是“加密技术的胜利”

marsbit51分钟前

空中云汇转向:从一年前鄙夷稳定币,到如今高调资本入局

跨境支付巨头空中云汇(Airwallex)近日领投了代币化金融结算网络Metal的种子轮融资,此举引发关注,因其创始人Jack Zhang一年前曾公开批评稳定币,质疑其降低汇款成本的效用,并认为加密货币缺乏实际用例。然而,此次投资标志着其态度发生显著转变。 Metal是一个面向代币化金融的全球结算网络与Layer-1区块链,旨在支持股票、债券、基金等各类金融资产的代币化结算,目标市场达十万亿美元级。空中云汇通过投资将为其支付网络引入代币化资产,结合自身在法币通道、全球支付场景方面的优势,形成战略协同。 尽管Jack Zhang在投资后仍坚持认为稳定币与加密货币本质不同,强调稳定币是法币的代币化形式,但其行动已表明了对稳定币及代币化赛道价值的重新评估。这一转变并非孤例,近年来传统金融巨头如摩根大通、Visa、Stripe等均在积极布局稳定币支付和代币化网络,反映出主流金融体系对链上结算效率革命的接纳。 空中云汇的投资逻辑并非全然认同加密货币,而是基于战略考量。面对稳定币在新兴市场、企业金融和链上结算等领域带来的结构性机会,以及可能重塑支付行业竞争格局的趋势,提前入场布局成为必要选择。这回答了其一年前的质疑:稳定币的价值至少已值得资本下注,而非置身事外。

marsbit1小时前

空中云汇转向:从一年前鄙夷稳定币,到如今高调资本入局

marsbit1小时前

交易

现货
活动图片