Radiant Capital hack — October 2024
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $50,000,000Published estimates range $50,000,000 to $53,000,000Price at time of incident |
| Method | Social engineeringmalware substituted transferOwnership payloads in the Safe multisig UI; 3 of 11 signers blind-signed |
| Chains | Arbitrum, BNB Chain |
| Attributed to | UNC4736, also tracked as AppleJeus and Citrine Sleet, assessed by Mandiant as having a DPRK nexusSuspected |
| Outcome | Project shut down |
What happened
On 16 October 2024 attackers took control of the multisig that administered Radiant Capital's lending markets and drained roughly $50 million from its Arbitrum and BNB Chain deployments. Radiant's post-mortem describes malware sitting between the signers and the Safe{Wallet} interface: signers saw and approved what looked like routine transactions while the payload sent to their hardware wallets was a transferOwnership call. Three of the eleven signers on the 3-of-11 Arbitrum multisig signed it. At 17:09:18 UTC control of the Arbitrum LendingPoolAddressesProvider passed to an attacker-controlled address, and the BNB Chain equivalent followed at 17:11:00 UTC. Malicious contracts had already been deployed on both chains on 2 October. An automated pause was triggered on Ethereum mainnet and a pause transaction was executed on Base before those markets could be drained. Beyond the core pools, the attackers exploited open approvals users had left in place to withdraw tokens directly from their accounts.
Mandiant, retained by Radiant, attributed the intrusion to UNC4736, also tracked as AppleJeus and Citrine Sleet, and assessed with high confidence that the group has a DPRK nexus. The initial compromise dates to 11 September 2024, when a developer received a Telegram message impersonating a former contractor carrying INLETDRIFT, a macOS backdoor disguised as a report on the Penpie hack.
Figures differ. Radiant's own post-mortem says approximately $50 million. The Block reported $51 million on the day. Crypto.news reports approximately $53 million. None of the funds were recovered. TVL fell to about $5 million within weeks of the breach, and in June 2026 Radiant's DAO announced that development, upgrades and expansion would cease and the protocol would move to a maintenance state, with the frontend online and users able to withdraw, repay and manage existing positions. The Defiant reported at the same time that no formal wind-down notice had been posted to Radiant's X account or its governance forum, and that TVL stood at $2.21 million.
Law enforcement
Radiant said it worked with U.S. law enforcement and the incident-response firm ZeroShadow to trace and freeze stolen assets. No indictment, arrest or sanctions designation tied to this incident was found in the sources reviewed.
Sources
- Radiant CapitalPrimary · retrieved 2026-08-01
- Radiant CapitalPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Radiant Capital hack — October 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/radiant-capitalhttps://itokenly.com/hacks/radiant-capitalPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.