BPOI Banner
Hackers Steal $243 Million In Bitcoin Scam Hackers Steal $243 Million In Bitcoin Scam

Radiant Capital Releases Post-Mortem Analysis of $50M Attack

Radiant Capital has released a detailed analysis of the October 16 exploit that led to the loss of more than $50 million in user funds.

According to the post-mortem, the attacker used highly advanced malware to poison transactions, enabling them to steal funds during a routine multi-signature process.

Attack Methodology Exploited Common Errors

It all started with the hacker compromising hard wallets belonging to three of the protocol’s core developers and injecting them with malware that mimicked legitimate transactions. As the developers signed what they believed were routine emissions adjustments, the malware executed unauthorized transactions in the background.

Radiant Capital reiterated that its contributors followed standard operating procedures to the letter in the fateful process. They simulated each transaction for accuracy on the full-stack Web3 infrastructure platform, Tenderly, while also putting them through individual review at every signature stage.

Despite these multiple layers of verification, front-end checks showed no visible signs of anomalies even as the malware wormed its way into the protocol’s systems.

What also stood out in the company’s assessment was how the attacker took advantage of common transaction failures to execute the hack. They used wallet resubmissions, often caused by gas price fluctuations or network congestion, as cover to collect the private keys, all while maintaining the appearance of normalcy.

The perpetrator then gained control of some smart contracts and eventually siphoned millions of dollars worth of cryptocurrencies, including USDC, wrapped BNB (wBNB), and Ethereum (ETH).

The actual amount stolen varies between $50 million and $58 million, depending on the source reporting it. However, the decentralized finance (DeFi) platform has stated the lower figure in its accounting of the incident.

FBI Tapped to Help Recover Stolen Funds

In the report, the cross-chain lender said it is working closely with U.S. law enforcement, including the FBI, as well as cybersecurity firms SEAL911 and ZeroShadow to track the stolen crypto.

Further, as a precaution, it advised users to revoke approvals across all chains, including Arbitrum, BSC, and Base. This step is in response to the exploiter capitalizing on open approvals to drain funds from accounts.

Radiant Capital has also created new cold wallets and adjusted signing thresholds to improve the platform’s security. Likewise, it has introduced a mandatory 72-hour delay for all contract upgrades and ownership transfers. It is meant to give the community enough time to check transactions before final execution.

However, given the level of sophistication in the breach, the firm has conceded that even these measures may not have prevented the attack.

DeFi exploits have grown at an alarming pace, and a couple of recent surveys paint a drab picture. According to PeckShield, there were more than 20 hacks in September, leading to more than $120 million in losses.

In addition, another on-chain security firm, Hacken, announced that more than $440 million stolen from crypto platforms in the third quarter of 2024 had been lost forever.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER 2024 at BYDFi Exchange: Up to $2,888 welcome reward, use this link to register and open a 100 USDT-M position for free!

Source link

Wayne Jones

https://cryptopotato.com/radiant-capital-releases-post-mortem-analysis-of-50m-attack/

2024-10-18 17:56:29

bitcoin
Bitcoin (BTC) $ 84,429.62 0.76%
ethereum
Ethereum (ETH) $ 1,660.15 4.81%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.14 0.93%
bnb
BNB (BNB) $ 589.47 0.54%
solana
Solana (SOL) $ 131.96 3.19%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.16398 0.74%
tron
TRON (TRX) $ 0.256034 3.53%
cardano
Cardano (ADA) $ 0.644231 0.33%
staked-ether
Lido Staked Ether (STETH) $ 1,657.37 5.01%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 84,280.58 0.49%
leo-token
LEO Token (LEO) $ 9.40 0.09%
avalanche-2
Avalanche (AVAX) $ 20.27 3.09%
chainlink
Chainlink (LINK) $ 12.97 2.01%
stellar
Stellar (XLM) $ 0.243298 0.30%
sui
Sui (SUI) $ 2.29 0.06%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 0.42%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,006.23 4.82%
usds
USDS (USDS) $ 1.00 0.02%
hedera-hashgraph
Hedera (HBAR) $ 0.168282 0.98%
the-open-network
Toncoin (TON) $ 2.80 1.42%
bitcoin-cash
Bitcoin Cash (BCH) $ 336.41 2.19%
litecoin
Litecoin (LTC) $ 77.87 0.30%
polkadot
Polkadot (DOT) $ 3.72 0.81%
hyperliquid
Hyperliquid (HYPE) $ 16.09 2.72%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.20%
bitget-token
Bitget Token (BGB) $ 4.28 0.52%
pi-network
Pi Network (PI) $ 0.740791 1.13%
ethena-usde
Ethena USDe (USDE) $ 0.998916 0.16%
weth
WETH (WETH) $ 1,674.90 4.90%
whitebit
WhiteBIT Coin (WBT) $ 27.78 0.13%
monero
Monero (XMR) $ 208.67 0.70%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,761.83 4.09%
uniswap
Uniswap (UNI) $ 5.50 3.17%
okb
OKB (OKB) $ 52.90 1.61%
pepe
Pepe (PEPE) $ 0.000008 4.37%
dai
Dai (DAI) $ 1.00 0.06%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 84,332.60 0.63%
aptos
Aptos (APT) $ 4.89 1.10%
ondo-finance
Ondo (ONDO) $ 0.890351 1.58%
gatechain-token
Gate (GT) $ 22.40 0.36%
tokenize-xchange
Tokenize Xchange (TKX) $ 33.66 0.21%
near
NEAR Protocol (NEAR) $ 2.16 0.67%
susds
sUSDS (SUSDS) $ 1.05 0.10%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
crypto-com-chain
Cronos (CRO) $ 0.086683 0.74%
internet-computer
Internet Computer (ICP) $ 4.88 3.68%
ethereum-classic
Ethereum Classic (ETC) $ 15.51 2.41%
mantle
Mantle (MNT) $ 0.691011 1.20%
bitcoin
Bitcoin (BTC) $ 84,429.62 0.76%
ethereum
Ethereum (ETH) $ 1,660.15 4.81%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.14 0.93%
bnb
BNB (BNB) $ 589.47 0.54%
solana
Solana (SOL) $ 131.96 3.19%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.16398 0.74%
tron
TRON (TRX) $ 0.256034 3.53%
cardano
Cardano (ADA) $ 0.644231 0.33%
staked-ether
Lido Staked Ether (STETH) $ 1,657.37 5.01%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 84,280.58 0.49%
leo-token
LEO Token (LEO) $ 9.40 0.09%
avalanche-2
Avalanche (AVAX) $ 20.27 3.09%
chainlink
Chainlink (LINK) $ 12.97 2.01%
stellar
Stellar (XLM) $ 0.243298 0.30%
sui
Sui (SUI) $ 2.29 0.06%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 0.42%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,006.23 4.82%
usds
USDS (USDS) $ 1.00 0.02%
hedera-hashgraph
Hedera (HBAR) $ 0.168282 0.98%
the-open-network
Toncoin (TON) $ 2.80 1.42%
bitcoin-cash
Bitcoin Cash (BCH) $ 336.41 2.19%
litecoin
Litecoin (LTC) $ 77.87 0.30%
polkadot
Polkadot (DOT) $ 3.72 0.81%
hyperliquid
Hyperliquid (HYPE) $ 16.09 2.72%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.20%
bitget-token
Bitget Token (BGB) $ 4.28 0.52%
pi-network
Pi Network (PI) $ 0.740791 1.13%
ethena-usde
Ethena USDe (USDE) $ 0.998916 0.16%
weth
WETH (WETH) $ 1,674.90 4.90%
whitebit
WhiteBIT Coin (WBT) $ 27.78 0.13%
monero
Monero (XMR) $ 208.67 0.70%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,761.83 4.09%
uniswap
Uniswap (UNI) $ 5.50 3.17%
okb
OKB (OKB) $ 52.90 1.61%
pepe
Pepe (PEPE) $ 0.000008 4.37%
dai
Dai (DAI) $ 1.00 0.06%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 84,332.60 0.63%
aptos
Aptos (APT) $ 4.89 1.10%
ondo-finance
Ondo (ONDO) $ 0.890351 1.58%
gatechain-token
Gate (GT) $ 22.40 0.36%
tokenize-xchange
Tokenize Xchange (TKX) $ 33.66 0.21%
near
NEAR Protocol (NEAR) $ 2.16 0.67%
susds
sUSDS (SUSDS) $ 1.05 0.10%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
crypto-com-chain
Cronos (CRO) $ 0.086683 0.74%
internet-computer
Internet Computer (ICP) $ 4.88 3.68%
ethereum-classic
Ethereum Classic (ETC) $ 15.51 2.41%
mantle
Mantle (MNT) $ 0.691011 1.20%