Radiant Capital halts Arbitrum markets after reported $4.5M flash loan attack

Cointelegraph發佈於 2024-01-02更新於 2024-01-03

文章摘要

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.

Cross-chain lending protocol Radiant Capital has paused its lending and borrowing markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of its newly created USDC Coin (USDC) markets.
“Today, we received a report of an issue with the newly created native USDC market on Arbitrum,” said Radiant in a Jan. 3 post on X (formerly Twitter), which they added was later validated by Radiant developers and the wider cybersecurity community.
Today, we received a report of an issue with the newly created native USDC market on Arbitrum. After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending/borrowing markets on Arbitrum temporarily while this is…
— Radiant Capital (@RDNTCapital) January 3, 2024
Blockchain security firm Beosin described the exploit as a flash loan attack — with the attacker exploiting a “rounding issue” in the codebase, “which led to a cumulative precision error.”
This ultimately allowed the “attacker to profit through repeated deposit() and withdraw() operations,” it wrote in a Jan. 3 post on X.
An earlier Jan. 2 post from PeckShield also identified the issue as caused by a “known rounding issue” in the current Compound/Aave codebase.
“The root cause is not new: It basically exploits a time window when a new market is activated in a lending market (forked from the popular Compound/Aave),” it added.
Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker: https://t.co/L7fXlF8VXP

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its… pic.twitter.com/8AdY7pjaKE
— Beosin Alert (@BeosinAlert) January 3, 2024
The exploiter managed to siphon a total of $4.5 million in Ether (ETH) from the protocol, according to data from Arbitrum block explorer Arbiscanner.
Radiant has since paused lending and borrowing markets on Arbitrum, and reassured investors that no additional funds were currently at risk. It promised a detailed postmortem, and pledged to restore normal operations once the investigation was completed.
“As a reminder, no action can be taken until the markets are unpaused on Arbitrum,” Radiant added.
Related: Orbit Bridge hack pushes December crypto theft to nearly $100M
Meanwhile, Crypto X has already been flooded with fake Radiant Capital accounts posting phishing links purporting to help users revoke approvals.

A fake Radiant Capital account attempts to trick unsuspecting users into clicking phishing links. Source: XRadiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. The protocol currently has around $315 million in total value locked, according to DefiLlama.
Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks

你可能也喜歡

Websea 三周年:行业洗牌期下,一家中型交易所的调整与选择

2026年的加密货币交易所行业呈现矛盾图景:一方面传统金融资产、RWA等持续扩张,另一方面部分老牌交易所却在退场。这意味着市场机会并不直接转化为中小型交易所的长期增长。在此背景下,成立三年的中型交易所Websea近期密集调整业务。 近期,Websea集中上线或升级了合约保险、复制交易、黄金白银CFD、储备金证明(PoR)等产品,并在阿拉木图联合主办全球RWA峰会。平台披露全球注册用户超150万,日均交易量约50亿美元。其调整主要围绕风险管理、多资产交易和资产透明度展开。 Websea成立于2023年熊市余波中。当前行业竞争分化,中型平台需在产品特色与用户运营中找到位置。其发展质量取决于用户留存与长期运营能力。 风险管理产品方面,Websea将合约保险、复制交易与VIP权益、新用户激励相结合,试图连接用户激励与后续交易体验。但其长期竞争力取决于规则清晰度、执行稳定性及数据持续披露。 在传统金融(TradFi)领域,交易所通过提供美股、指数、大宗商品等CFD产品来扩展交易标的,旨在提升用户停留时间,平滑市场波动影响。然而,这类产品涉及复杂的价格源与风控,能否成为第二增长曲线有待验证。 在资产透明与区域拓展上,Websea发布了首期PoR,提供了资产核验入口,其价值需结合更新的连续性与审计严谨性来看。同时,其在阿拉木图主办RWA峰会,意在连接中亚地区的产业资源,寻求资产端机会,但距离形成可交易产品仍有诸多环节。 总结而言,Websea三周年的布局反映了行业竞争焦点的变化:从追求流量转向注重风险管理、资产透明度和全球/区域资产拓展。对于Websea而言,接下来的关键并非产品数量,而是这些布局能否转化为可持续的用户留存、流动性及可验证的业务增长,这需要更长时间的数据来证明。

marsbit29 分鐘前

Websea 三周年:行业洗牌期下,一家中型交易所的调整与选择

marsbit29 分鐘前

英伟达「最大产品周期」来了?伯恩斯坦将目标价上调至400美元

伯恩斯坦在8月27日的报告中,将英伟达目标价从315美元大幅上调至400美元,并维持“跑赢大盘”评级。其核心观点是,英伟达的增长动力正从当前的Blackwell平台延伸至下一代Rubin平台,后者已开始实质性放量,可能推动公司迎来史上最大的产品周期。 财报显示,英伟达第二财季数据中心收入达890亿美元,超预期增长。公司给出的第三财季营收指引中值为1080亿美元,其中数据中心收入可能突破1000亿美元,Rubin预计贡献约20%。管理层对2028财年(对应2027自然年)的增长预期更为乐观,伯恩斯坦据此将英伟达2028财年营收预测从5396亿美元上调至6903亿美元,非GAAP每股收益预测也相应提高。 报告也指出挑战:内存成本上涨导致毛利率面临短期压力,预计第三、第四财季会有所下滑。但伯恩斯坦认为,在营收规模快速扩张下,整体盈利增长依然强劲。此外,英伟达的供应链能力成为关键壁垒,其供应相关承诺已激增至2790亿美元,庞大的资产负债表有助于锁定关键资源,构建生态护城河。 伯恩斯坦的新目标价基于盈利预测的上调,而非估值倍数扩张。其实现依赖于Rubin顺利爬坡、供应链支持增长以及云厂商维持高资本开支等假设。报告认为,市场对英伟达2027年的盈利预测可能面临集中上修,股价未来空间将取决于公司将庞大订单转化为收入的能力。

marsbit30 分鐘前

英伟达「最大产品周期」来了?伯恩斯坦将目标价上调至400美元

marsbit30 分鐘前

交易

現貨
活动图片