{"investigation":{"slug":"radiant-capital","entity_name":"Radiant Capital","trust_score":18,"severity_base":null,"score_modifier":-25,"confidence":0.88,"status":"draft","content_type":"investigation","summary":"Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that launched in July 2022 on Arbitrum. In 2024 it suffered two separate security incidents totaling approximately $54.5 million in losses: a $4.5 million flash loan exploit in January 2024 and a $50 million multisig compromise in October 2024 attributed by Mandiant to North Korean state-sponsored hackers (UNC4736/Citrine Sleet). The October 2024 hack reduced TVL by roughly 98%, led to major exchange delistings, and stolen funds were subsequently laundered through Tornado Cash.","sections":[{"content":"Radiant Capital is a DeFi lending protocol that describes itself as an omnichain money market, enabling users to deposit assets on one blockchain and borrow across multiple supported chains. It was launched in July 2022 as a fair launch on Arbitrum without external venture funding, using LayerZero for cross-chain interoperability and Stargate's stable router interface for asset transfers. The protocol supports assets including USDC, WBTC, ETH, and liquid staking derivatives. Its native governance and incentive token, RDNT, has a total supply of one billion tokens. A V2 upgrade expanded the protocol to BNB Chain, Ethereum mainnet, and Base.","heading":"Protocol Overview","sources":[{"url":"https://www.nansen.ai/post/what-is-radiant-capital-cross-chain-defi-explained","name":"nansen.ai","type":"other","credibility":3},{"url":"https://www.gate.com/learn/articles/radiant-capital-fragmented-liquidity-integration-for-cross-chain-lending/1875","name":"gate.com","type":"other","credibility":3},{"url":"https://docs.radiant.capital/radiant/radiantv1","name":"docs.radiant.capital","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 2, 2024, Radiant Capital's newly activated native USDC lending market on Arbitrum was exploited for approximately $4.5 million (roughly 1,900 ETH) within six seconds of the market going live. The attacker exploited a known rounding precision error in Radiant's Compound/Aave-forked codebase. By manipulating a critical index parameter through repeated deposit and withdrawal operations, the attacker inflated the parameter used as a denominator in share-price calculations, triggering cumulative rounding errors that allowed them to drain funds without proportional token burns. Radiant halted its Arbitrum markets in response and subsequently made a recovery payment of approximately 1,190 ETH ($2.6 million) toward the outstanding bad debt, with remaining debt handled through operating expense funds per governance proposal RFP-27.","heading":"January 2024 Flash Loan Exploit ($4.5M)","sources":[{"url":"https://cointelegraph.com/news/radiant-capital-lending-protocol-flash-loan-attack-arbitrum","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://dailycoin.com/hacker-exploits-radiant-capital-for-4-5-million-ethereum/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/radiant-capital-repayment-flash-loan-exploit/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/radiant-capital-hack","name":"quillaudits.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 16, 2024, Radiant Capital suffered its second and far more destructive attack, losing approximately $50 million from its lending pools on Arbitrum and BNB Chain. The attack originated on September 11, 2024, when a Radiant developer received a Telegram message impersonating a known former contractor, purportedly sharing a PDF about smart contract auditing. The ZIP file (\"Penpie_Hacking_Analysis_Report.zip\") contained INLETDRIFT, a sophisticated macOS backdoor malware (MD5: FF15427D45B84E79B2E81199613041BB) that established persistence via LaunchDaemons and communicated with the command server at \"atokyonews[.]com\". The malware silently signed malicious blockchain transactions in the background while displaying legitimate transaction data on the Safe{Wallet} front-end interface, making the threat virtually undetectable during standard review. At least three developers' hardware wallets were compromised, providing the three-of-eleven signatures needed to satisfy the protocol's multisig threshold and execute a transferOwnership() call that handed control of Radiant's lending pool contracts to the attackers. Cybersecurity firm Mandiant, retained by Radiant for forensic investigation, attributed the attack with high confidence to UNC4736, also tracked as Citrine Sleet or AppleJeus, a threat actor assessed to have a DPRK nexus with ties to North Korea's Reconnaissance General Bureau (RGB). The U.S. Army's 780th Military Intelligence Brigade (Cyber) publicly confirmed the Mandiant attribution.","heading":"October 2024 Multisig Compromise and North Korea Attribution ($50M)","sources":[{"url":"https://www.coindesk.com/tech/2024/12/09/radiant-capital-says-north-korean-hackers-behind-50-million-attack-in-october","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.securityweek.com/radiant-capital-50-million-heist-blamed-on-north-korean-hackers/","name":"securityweek.com","type":"other","credibility":3},{"url":"https://therecord.media/radiant-capital-heist-north-korea","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/radiant-links-50-million-crypto-heist-to-north-korean-hackers/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Radiant Capital operated a 3-of-11 multisig scheme at the time of the October 2024 attack, meaning only three of eleven possible signatories were required to authorize critical protocol transactions. This low threshold significantly widened the attack surface: a nation-state adversary needed to compromise only three devices from a pool of eleven targets. Compounding the risk, Ledger hardware wallets do not natively parse Gnosis Safe transaction data, meaning signers were effectively blind-signing the malicious transferOwnership() calls. The Safe{Wallet} front-end displayed benign transaction data, and traditional simulation tools showed no discrepancies, making detection during routine review impossible. After the hack, Radiant's DAO raised the multisig threshold to 4-of-7 (57%), reducing both the target pool and increasing the share of devices an attacker must compromise.","heading":"Multisig Security Model Failure","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-radiant-capital-hack-october-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.auditone.io/blog-posts/unpacking-multisig-hacks-in-defi-radiant-capitals-case","name":"auditone.io","type":"other","credibility":3},{"url":"https://hacken.io/insights/radiant-hack-review/","name":"hacken.io","type":"other","credibility":3},{"url":"https://nomoslabs.io/blog/radiant-capital-hack-multi-sig-compromise-drained-50m","name":"nomoslabs.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the October 2024 theft, Radiant engaged zeroShadow and Hypernative for on-chain asset tracking, and enlisted SEAL 911 for additional incident response. The protocol also worked with U.S. law enforcement to attempt to freeze stolen assets. However, the attackers began laundering the proceeds in stages. In August 2025, the exploiter swapped approximately 3,091 ETH for 13.26 million DAI stablecoins and subsequently reconverted the DAI back into ETH through a series of intermediary wallets. On October 23, 2025, blockchain analytics firm CertiK reported that the exploiter deposited 2,834.6 ETH (approximately $10.8 million) into the Tornado Cash mixer. On October 31, 2025, PeckShield reported an additional deposit of 5,411.8 ETH (approximately $20.7 million) into Tornado Cash. The laundered funds originated from bridged assets via the Stargate Bridge and Synapse Bridge. As of late 2025, the majority of stolen funds had not been recovered.","heading":"Post-Hack Fund Recovery and Laundering","sources":[{"url":"https://coincentral.com/radiant-capital-hacker-launders-10-8m-through-tornado-cash-mixer/","name":"coincentral.com","type":"other","credibility":3},{"url":"https://coinjournal.net/news/radiant-capital-hacker-transfers-5400-eth-to-tornado-cash-peckshield/","name":"coinjournal.net","type":"other","credibility":3},{"url":"https://crypto.news/radiant-capital-hacker-moves-10-8m-into-tornado-cash/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"The October 2024 exploit caused Radiant Capital's total value locked (TVL) to collapse by approximately 98%, falling from roughly $300 million to under $8 million. The RDNT token reached an all-time low of approximately $0.017 in April 2025. The Radiant DAO approved a remediation plan targeting initial payouts to affected users in Q3/Q4 2025, funded in part through a proposed Guardian Fund — a protocol-backed reserve intended to cover future extreme loss scenarios. OKX and Crypto.com delisted RDNT in January 2025, reducing liquidity and market access. Radiant also began migrating its token to the OFT (Omnichain Fungible Token) standard as part of a V2 relaunch. The protocol's official website remains active at radiant.capital, but community sentiment remains predominantly bearish given the severity of losses and the absence of substantive fund recovery.","heading":"Protocol Recovery and Current Status","sources":[{"url":"https://www.coindesk.com/tech/2024/10/16/radiant-capital-loses-50m-to-blockchain-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/cmc-ai/radiant-capital/latest-updates/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://medium.com/@RadiantCapital/radiant-capital-recovery-bounty-program-b4d116c691d0","name":"medium.com","type":"other","credibility":3},{"url":"https://www.datawallet.com/crypto/radiant-capital-explained","name":"datawallet.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Radiant Capital was founded in 2022 and is reportedly headquartered in Hong Kong. The protocol launched as a fair launch without external venture funding. However, the founding team's identities are not publicly disclosed in any Tier 1 or Tier 2 source reviewed for this investigation. The protocol's governance operates through its DAO and RDNT token holders. The anonymous or pseudonymous nature of the core team is a risk signal, particularly given the severity and nature of the two security incidents, as it limits accountability and the ability of affected users to pursue legal remedies.","heading":"Team Identity and Transparency","sources":[{"url":"https://www.nansen.ai/post/what-is-radiant-capital-cross-chain-defi-explained","name":"nansen.ai","type":"other","credibility":3},{"url":"https://radiant.capital/","name":"radiant.capital","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-07","event":"Radiant Capital launches as a fair-launch omnichain lending protocol on Arbitrum, built on LayerZero.","source":"","date_original":"2022-07-01"},{"date":"2024-01-02","event":"Flash loan exploit targets the newly launched native USDC market on Arbitrum; approximately $4.5 million (1,900 ETH) drained in six seconds via a cumulative rounding precision error in Compound/Aave-forked code.","source":""},{"date":"2024-01-02","event":"Radiant halts all Arbitrum lending and borrowing markets in response to the flash loan exploit.","source":""},{"date":"2024-09-11","event":"North Korean UNC4736 threat actor sends a deceptive Telegram message to a Radiant developer, impersonating a former contractor and delivering the INLETDRIFT macOS backdoor malware via a ZIP file.","source":""},{"date":"2024-10-16","event":"Radiant Capital loses approximately $50 million from its Arbitrum and BNB Chain lending pools; attackers used malware-compromised developer hardware wallets to satisfy the 3-of-11 multisig threshold and execute a transferOwnership() call.","source":""},{"date":"2024-10-17","event":"Radiant Capital publishes an initial post-mortem; retains Mandiant for forensic investigation, zeroShadow and Hypernative for on-chain tracking, and SEAL 911 for incident response.","source":""},{"date":"2024-12-06","event":"Radiant Capital publishes updated incident findings, publicly attributing the October attack to North Korean state-sponsored hackers.","source":""},{"date":"2024-12-09","event":"Mandiant formally attributes the October 2024 attack to UNC4736 (also known as Citrine Sleet / AppleJeus), assessed with high confidence to have a DPRK nexus aligned with the Reconnaissance General Bureau.","source":""},{"date":"2025","event":"OKX and Crypto.com delist the RDNT token, reducing liquidity and market access.","source":"","date_original":"2025-01-01"},{"date":"2025-04","event":"RDNT token reaches an all-time low of approximately $0.017 amid bearish sentiment and TVL collapse.","source":"","date_original":"2025-04-01"},{"date":"2025-08","event":"The October 2024 exploiter swaps approximately 3,091 ETH for 13.26 million DAI and begins moving proceeds through intermediary wallets.","source":"","date_original":"2025-08-01"},{"date":"2025-10-23","event":"CertiK reports the Radiant Capital exploiter deposited 2,834.6 ETH (approximately $10.8 million) into the Tornado Cash mixer.","source":""},{"date":"2025-10-31","event":"PeckShield reports the Radiant Capital exploiter deposited an additional 5,411.8 ETH (approximately $20.7 million) into Tornado Cash.","source":""}],"sources_used":[{"url":"https://www.nansen.ai/post/what-is-radiant-capital-cross-chain-defi-explained","name":"nansen.ai","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.gate.com/learn/articles/radiant-capital-fragmented-liquidity-integration-for-cross-chain-lending/1875","name":"gate.com","type":"other","archive_url":"https://web.archive.org/web/20260901042626/https://www.gate.com/learn/articles/radiant-capital-fragmented-liquidity-integration-for-cross-chain-lending/1875","credibility":3,"archive_timestamp":"2026-09-01T04:26:26+00:00"},{"url":"https://docs.radiant.capital/radiant/radiantv1","name":"docs.radiant.capital","type":"other","archive_url":"http://web.archive.org/web/20260611163437/https://docs.radiant.capital/radiant/radiantv1","credibility":3,"archive_timestamp":"2026-06-11T16:34:37+00:00"},{"url":"https://cointelegraph.com/news/radiant-capital-lending-protocol-flash-loan-attack-arbitrum","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260825111813/https://cointelegraph.com/news/radiant-capital-lending-protocol-flash-loan-attack-arbitrum","credibility":3,"archive_timestamp":"2026-08-25T11:18:13+00:00"},{"url":"https://dailycoin.com/hacker-exploits-radiant-capital-for-4-5-million-ethereum/","name":"dailycoin.com","type":"other","archive_url":"https://web.archive.org/web/20260830165438/https://dailycoin.com/hacker-exploits-radiant-capital-for-4-5-million-ethereum/","credibility":3,"archive_timestamp":"2026-08-30T16:54:38+00:00"},{"url":"https://www.cryptopolitan.com/radiant-capital-repayment-flash-loan-exploit/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260215180851/https://www.cryptopolitan.com/radiant-capital-repayment-flash-loan-exploit/","credibility":3,"archive_timestamp":"2026-02-15T18:08:51+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/radiant-capital-hack","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260515100939/https://www.quillaudits.com/blog/hack-analysis/radiant-capital-hack","credibility":3,"archive_timestamp":"2026-05-15T10:09:39+00:00"},{"url":"https://www.coindesk.com/tech/2024/12/09/radiant-capital-says-north-korean-hackers-behind-50-million-attack-in-october","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20250922201844/https://www.coindesk.com/tech/2024/12/09/radiant-capital-says-north-korean-hackers-behind-50-million-attack-in-october","credibility":3,"archive_timestamp":"2025-09-22T20:18:44+00:00"},{"url":"https://www.securityweek.com/radiant-capital-50-million-heist-blamed-on-north-korean-hackers/","name":"securityweek.com","type":"other","archive_url":"http://web.archive.org/web/20260305075602/https://www.securityweek.com/radiant-capital-50-million-heist-blamed-on-north-korean-hackers/","credibility":3,"archive_timestamp":"2026-03-05T07:56:02+00:00"},{"url":"https://therecord.media/radiant-capital-heist-north-korea","name":"therecord.media","type":"other","archive_url":"http://web.archive.org/web/20260411014133/https://therecord.media/radiant-capital-heist-north-korea","credibility":3,"archive_timestamp":"2026-04-11T01:41:33+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/radiant-links-50-million-crypto-heist-to-north-korean-hackers/","name":"bleepingcomputer.com","type":"other","archive_url":"http://web.archive.org/web/20260410185850/https://www.bleepingcomputer.com/news/security/radiant-links-50-million-crypto-heist-to-north-korean-hackers/","credibility":3,"archive_timestamp":"2026-04-10T18:58:50+00:00"},{"url":"https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","name":"decrypt.co","type":"other","archive_url":"https://web.archive.org/web/20260830165458/https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","credibility":3,"archive_timestamp":"2026-08-30T16:54:58+00:00"},{"url":"https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260714170524/https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e","credibility":3,"archive_timestamp":"2026-07-14T17:05:24+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-radiant-capital-hack-october-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260609212631/https://www.halborn.com/blog/post/explained-the-radiant-capital-hack-october-2024","credibility":3,"archive_timestamp":"2026-06-09T21:26:31+00:00"},{"url":"https://www.auditone.io/blog-posts/unpacking-multisig-hacks-in-defi-radiant-capitals-case","name":"auditone.io","type":"other","archive_url":"http://web.archive.org/web/20260414053531/https://www.auditone.io/blog-posts/unpacking-multisig-hacks-in-defi-radiant-capitals-case","credibility":3,"archive_timestamp":"2026-04-14T05:35:31+00:00"},{"url":"https://hacken.io/insights/radiant-hack-review/","name":"hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260420184325/https://hacken.io/insights/radiant-hack-review/","credibility":3,"archive_timestamp":"2026-04-20T18:43:25+00:00"},{"url":"https://nomoslabs.io/blog/radiant-capital-hack-multi-sig-compromise-drained-50m","name":"nomoslabs.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coincentral.com/radiant-capital-hacker-launders-10-8m-through-tornado-cash-mixer/","name":"coincentral.com","type":"other","archive_url":"http://web.archive.org/web/20251027041147/https://coincentral.com/radiant-capital-hacker-launders-10-8m-through-tornado-cash-mixer/","credibility":3,"archive_timestamp":"2025-10-27T04:11:47+00:00"},{"url":"https://coinjournal.net/news/radiant-capital-hacker-transfers-5400-eth-to-tornado-cash-peckshield/","name":"coinjournal.net","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://crypto.news/radiant-capital-hacker-moves-10-8m-into-tornado-cash/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251112023546/https://crypto.news/radiant-capital-hacker-moves-10-8m-into-tornado-cash/","credibility":3,"archive_timestamp":"2025-11-12T02:35:46+00:00"},{"url":"https://www.coindesk.com/tech/2024/10/16/radiant-capital-loses-50m-to-blockchain-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260420091309/https://www.coindesk.com/tech/2024/10/16/radiant-capital-loses-50m-to-blockchain-exploit","credibility":3,"archive_timestamp":"2026-04-20T09:13:09+00:00"},{"url":"https://coinmarketcap.com/cmc-ai/radiant-capital/latest-updates/","name":"coinmarketcap.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/@RadiantCapital/radiant-capital-recovery-bounty-program-b4d116c691d0","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20250919100348/https://medium.com/@RadiantCapital/radiant-capital-recovery-bounty-program-b4d116c691d0","credibility":3,"archive_timestamp":"2025-09-19T10:03:48+00:00"},{"url":"https://www.datawallet.com/crypto/radiant-capital-explained","name":"datawallet.com","type":"other","archive_url":"http://web.archive.org/web/20260217111353/https://www.datawallet.com/crypto/radiant-capital-explained","credibility":3,"archive_timestamp":"2026-02-17T11:13:53+00:00"},{"url":"https://radiant.capital/","name":"radiant.capital","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-10T06:08:15.590201+00:00","updated_at":"2026-09-01T04:31:09.411426+00:00"}}