Summary
Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that suffered two significant security incidents in 2024: a $4.5 million flash loan exploit in January 2024 and a far more devastating $50 million multisig compromise in October 2024. The October hack, attributed by Mandiant with high confidence to North Korean state-sponsored group UNC4736 (Citrine Sleet / AppleJeus), involved a months-long social engineering campaign, macOS malware deployment on developer devices, and manipulation of hardware wallet signing interfaces to drain funds across BNB Chain and Arbitrum.
Connected Entities
1 entities- + 1 more
Timeline(11 events)
2022-07-01
Radiant Capital launches RDNT token on Arbitrum via Sushiswap fair launch.
2024-01-02
Flash loan exploit drains $4.5 million ETH from newly activated USDC market on Arbitrum via rounding error in liquidityIndex calculation.
2024-01-03
Radiant pauses Arbitrum lending and borrowing markets; promises post-mortem and user repayment.
2024-09-11
North Korean UNC4736 attacker sends malicious Telegram message to Radiant developer, impersonating a former contractor; INLETDRIFT macOS malware deployed via ZIP file.
2024-10-16
Attackers exploit compromised hardware wallets of at least 3 of 11 multisig signers to execute transferOwnership() on LendingPoolAddressesProvider; approximately $50–53 million drained from BSC and Arbitrum markets. Backdoor removed within 3 minutes of theft.
2024-10-17
Radiant publishes initial post-mortem; engages Mandiant, zeroShadow, Hypernative, and SEAL 911.
2024-10-24
On-chain tracking confirms hacker bridges $52M in stolen funds to Ethereum.
2024-12-06
Radiant Capital publishes updated incident report attributing attack to UNC4736 (North Korea) based on Mandiant forensic analysis.
2024-12-09
Public attribution of attack to DPRK-linked UNC4736 / Citrine Sleet / AppleJeus group reported by major media.
2025-08-01
On-chain monitors observe hacker actively trading stolen ETH and DAI; stolen portfolio value reportedly grows from $53M to over $94M through ETH appreciation and active arbitrage.
2025-10-01
Hacker deposits 2,834.6 ETH (approximately $10.8M) into sanctioned mixer Tornado Cash, substantially reducing recovery prospects.
Decision Log
- hash: BBbf816uKC6jCkXMQW8B5FdyEjogoa3q2hQQL8kXevP4
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:36 AM
last updated: 5/19/2026, 9:12:24 PM
avoid.net — verified advice for a post-truth world