Radiant Capital (Arbitrum USDC market) hack — January 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 3, 2024 |
| Target type | Lending protocol |
| Loss | $4,500,000Published estimates range $4,500,000 to $4,750,000Price at time of incident |
| Method | Contract logic errorRadiant activated a new native USDC market on Arbitrum with empty reserves. In that state the liquidityIndex, which tracks accrued interest per unit of deposit, can be inflated by rounding, because each flash loan fee is divided across a negligible total supply and rounds up sharply. The attacker made a small deposit, donated USDC to the reserve and took a rapid series of flash loans to drive the index up, then borrowed 1,900 WETH against a single rToken position valued at a large multiple of what had actually been deposited. Beosin and PeckShield identified this as a known rounding weakness in the Aave/Compound-derived codebase that appears when a market is first activated with no liquidity. Radiant published the attacker address 0x826d5f4d8084980366f975e10db6c4cf1f9dde6d, the market initialisation transaction 0x0e5330ad77b9b806cb9f6ea595d58552f341dbad0691e0599ab5f1caf214c247 and the exploit deployment transaction 0x81a1414641bc823cd623208ba4c19a6cfc94f363050487bb122c15dceadc8937, about five seconds apart. |
| Chains | Arbitrum |
| Outcome | Users reimbursed |
What happened
Radiant Capital's Arbitrum deployment lost 1,900 WETH on 2 January 2024 at 18:53:23 UTC, about five seconds after a new native USDC lending market was activated. Radiant's post-mortem quantifies the loss only in ETH and gives no dollar figure; Cointelegraph and crypto.news, drawing on analysis by Beosin and PeckShield, valued it at about $4.5 million, consistent with the price of ETH at the time.
The new market went live with empty reserves. In that state the liquidityIndex, which tracks accrued interest per unit of deposit, can be inflated by rounding: with a negligible total supply, each flash loan fee is divided across almost nothing and rounds up sharply. The attacker made a small deposit, then donated USDC to the reserve and took a rapid series of flash loans, each of which pushed the index higher. Their single rToken position was then valued at a large multiple of what had actually been deposited, and they borrowed 1,900 WETH against it. Beosin described a rounding and cumulative precision error, and PeckShield identified the issue as a known rounding weakness in the Aave and Compound derived codebase that appears when a market is first activated with no liquidity.
Radiant paused its Arbitrum lending and borrowing markets within hours. Through governance proposal RFP-27 the DAO agreed to repay the resulting bad debt from operational funds over roughly 90 days; 1,190 ETH had been repaid by the time the post-mortem was published, with about 720 ETH outstanding. Radiant also offered a $100,000 bounty for information identifying the attacker, who has not been publicly named.
This is a separate incident from the October 2024 compromise of Radiant's multisig signing devices.
Sources
- Radiant CapitalPrimary · retrieved 2026-08-01
- Cointelegraph (syndicated on TradingView)Secondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@RadiantCapital/post-mortem-report-radiant-capital-aea46cb985ae
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Radiant Capital (Arbitrum USDC market) hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/radiant-capital-usdc-markethttps://itokenly.com/hacks/radiant-capital-usdc-marketPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.