Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Radix
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 449052832
- Off-chain at
- 2026-09-21T12:16:27.879Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- gML3yVgr2fsLPR9E3prvLg7drvwadZyBrhmeVphaF5g
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (18882 chars)
{"actor":"system:backfill","investigation_id":"dee50fd0-098b-4e22-8034-37f39cea49cb","kind":"publish","page_slug":"radix","published_at":"2026-09-21T12:16:27.756Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Radix","sections":[{"content":"Radix is a layer-1 distributed ledger protocol purpose-built for decentralized finance (DeFi). Its origins trace to May 2013, when founder Dan Hughes — who had a background in telecommunications software — began developing the project on Bitcointalk under the name eMunie. The project was renamed Radix and restructured in 2017 when Piers Ridyard joined as CEO, with early funding provided by Taavet Hinrikus (co-founder of Wise, formerly TransferWise) and LocalGlobe, a London-based venture fund.\n\nThe protocol's key technical differentiators include the Cerberus consensus algorithm, a cross-shard atomically composable protocol first demonstrated in 2020, and Scrypto, Radix's asset-oriented smart contract programming language released in December 2021. Radix launched its Olympia mainnet on July 28, 2021, and upgraded to the Babylon mainnet — enabling full smart contract functionality — on September 28, 2023.\n\nDan Hughes, the founder and original architect of the network, died unexpectedly from natural causes on July 27, 2025. His death triggered a reported 40% sell-off in the XRD token. As of September 2026, RDX Works continues to operate the project under CEO Piers Ridyard. The XRD token trades at approximately $0.00056 USD with a market capitalization of roughly $7.6 million, down approximately 99% from its April 2023 peak.","heading":"Background and Project Overview","severity":"low","sources":[{"credibility":2,"name":"What is Radix DLT? | Messari","type":"research","url":"https://messari.io/project/radix-dlt/profile"},{"credibility":1,"name":"In Memory of Dan Hughes, Founder of Radix | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/in-memory-of-dan-hughes-founder-of-radix"},{"credibility":2,"name":"Radix (XRD) price and market cap | CoinMarketCap","type":"other","url":"https://coinmarketcap.com/currencies/radix-protocol/"},{"credibility":1,"name":"Radix Olympia Mainnet Is Coming — June 30th 2021 | Radix DLT on Medium","type":"official","url":"https://radixdlt.medium.com/radix-olympia-mainnet-is-coming-june-30th-2021-375c18cf6f26"}]},{"content":"On August 31, 2026, an attacker exploited a vulnerability in the Radix Engine's vault-authorization system, draining approximately $1.3 million in bridged assets over a period of roughly 55 minutes (16:02–16:57 UTC) across 26 transactions. The stolen assets comprised 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wrapped Bitcoin (wBTC), 536.16 SOL, and 32.91 BNB. An additional 13,000 XRD was taken to pay transaction fees. The attacker routed the stolen funds through the Hyperlane cross-chain bridge to Ethereum, BNB Chain, and Solana, and subsequently converted the assets to ETH.\n\nThe Radix Foundation's public incident report confirmed that the flaw allowed a transaction to identify another user's vault by its internal address and invoke the vault's withdrawal function without presenting valid ownership credentials. The engine failed to enforce the ownership boundary that should have rejected such a request. The Foundation noted that the vulnerability's blast radius was not limited to bridged assets — the flaw could theoretically have been used against any vault on the network, including tokens, application state, and liquidity pool holdings.\n\nThe Foundation reported the incident as a crime to the States of Jersey Police and to UK law enforcement through Action Fraud, and stated that forensic evidence was provided to both agencies. As of the time of reporting, no attacker identity had been publicly disclosed and no stolen funds had been recovered.","heading":"August 2026 Vault-Authorization Exploit","severity":"critical","sources":[{"credibility":1,"name":"Public Incident Report: Vault-Authorisation Vulnerability and Loss of Network Liveness | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"credibility":2,"name":"3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt | CryptoSlate","type":"news_article","url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"},{"credibility":2,"name":"A Bug Hidden Since 2023 Drained $1.3M and Froze Radix for 10 Days | CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/bug-hidden-since-2023-drained-13m-froze-radix/"},{"credibility":2,"name":"3-Year-Old Bug Causes $1.3M Theft and 10-Day Radix Blockchain Halt | KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/3-year-old-bug-causes-1-3m-theft-and-10-day-radix-blockchain-halt"}]},{"content":"The vulnerability was introduced during a routine code refactoring of the Radix Engine conducted by RDX Works in June 2023. According to the Radix Foundation's incident report, the defect arose from three individually reasonable behaviors in the engine's call-frame reference model combining into an unsafe execution path — specifically, a restricted vault reference being reusable in the context of an ordinary withdrawal call without triggering an authorization check.\n\nThe flaw went undetected by internal code review at the time of its introduction and subsequently remained undetected through an independent security audit conducted by Zellic in August 2024, despite that audit's scope covering the engine kernel in which the defect sat. The Babylon mainnet upgrade, completed September 28, 2023 — after the vulnerability was introduced — brought the buggy code into full smart contract production.\n\nThe Radix Foundation's post-incident report stated that the attacker appeared to have used AI-assisted code-analysis tools to locate the gap, a factor the Foundation said it was incorporating into future security review processes. In its remediation commitments, the Foundation announced plans to add regression tests targeting vault-access paths, strengthen security review procedures, and formalize the emergency validator coordination procedure used to halt the network.","heading":"Vulnerability Origin and Audit Failures","severity":"high","sources":[{"credibility":1,"name":"Public Incident Report: Vault-Authorisation Vulnerability and Loss of Network Liveness | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"credibility":2,"name":"Zellic — Radix Audit Reports","type":"research","url":"https://reports.zellic.io/publications/radix"},{"credibility":2,"name":"3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt | CryptoSlate","type":"news_article","url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"}]},{"content":"Following community detection of unauthorized withdrawals at approximately 17:37 UTC on August 31, 2026, Radix validators coordinated to voluntarily remove enough staked XRD from active consensus participation to prevent the network from reaching the supermajority threshold required to finalize transactions. Network liveness was deliberately broken between approximately 20:30 and 23:30 UTC on August 31, halting all transaction finalization and preventing the attacker from conducting further withdrawals.\n\nThe Hyperlane bridge infrastructure was separately disabled between 17:53 and 18:09 UTC to prevent additional cross-chain asset movement.\n\nThe network remained halted for over 10 days while developers built, reviewed, and deployed a patch. The fix was verified by independent auditors including Zellic, Hacken, and SEAL 911 before reactivation. Normal transaction finalization resumed on September 11, 2026.\n\nA consensus halt of this duration — more than 10 days on a live layer-1 network — is an unusual and significant reliability event. It reflects both the severity of the vulnerability (the team judged that resuming consensus before a fix was deployed would have exposed all vaults to potential further exploitation) and the network's capacity for coordinated validator response. Users, applications, and exchange integrations were unable to settle transactions on-chain for the entirety of this period.","heading":"10-Day Network Consensus Halt","severity":"critical","sources":[{"credibility":1,"name":"Public Incident Report: Vault-Authorisation Vulnerability and Loss of Network Liveness | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"credibility":2,"name":"3-Year-Old Radix Bug Triggers $1.3M Theft and 10-Day Network Halt | KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/3-year-old-radix-bug-triggers-1-3m-theft-and-10-day-network-halt"},{"credibility":2,"name":"A Bug Hidden Since 2023 Drained $1.3M and Froze Radix for 10 Days | CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/bug-hidden-since-2023-drained-13m-froze-radix/"}]},{"content":"The native XRD token trades at approximately $0.00056 USD as of September 2026, with a circulating supply of approximately 13.5 billion XRD and a market capitalization of roughly $7.6 million (CoinMarketCap rank approximately #1061). This represents a decline of approximately 99% from the token's April 2023 all-time high.\n\nThe death of founder Dan Hughes in July 2025 was reported to have triggered an immediate 40% sell-off in XRD. The August 2026 exploit and subsequent 10-day network halt occurred against this backdrop of significantly diminished market capitalization and reduced ecosystem activity. No information was found indicating that Radix as an organization has engaged in any regulatory violations, fraud, or misrepresentation of funds. The token's steep decline appears attributable to broader market dynamics, loss of the founding technical lead, and the August 2026 security incident rather than any alleged misconduct by RDX Works.","heading":"Token Performance and Market Context","severity":"medium","sources":[{"credibility":2,"name":"Radix (XRD) price and market cap | CoinMarketCap","type":"other","url":"https://coinmarketcap.com/currencies/radix-protocol/"},{"credibility":1,"name":"In Memory of Dan Hughes, Founder of Radix | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/in-memory-of-dan-hughes-founder-of-radix"},{"credibility":2,"name":"A Bug Hidden Since 2023 Drained $1.3M and Froze Radix for 10 Days | CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/bug-hidden-since-2023-drained-13m-froze-radix/"}]},{"content":"Following network restoration on September 11, 2026, the Radix Foundation published a detailed public incident report disclosing the technical root cause, the timeline of the attack and response, the audit history, and its planned remediation steps. The report was notable for its transparency in acknowledging that a paid independent audit (Zellic, August 2024) failed to catch the flaw, and for explicitly noting the possibility of AI-assisted exploitation tooling.\n\nThe patch deployed on September 11 prevents a restricted vault reference from being passed into a context where ordinary withdrawal functions can be called, closing the specific execution path the attacker used. Post-patch code reviews were independently verified by Zellic, Hacken, and SEAL 911, none of which identified critical issues in the corrected code.\n\nThe Foundation committed to three categories of follow-up action: (1) adding regression tests that specifically cover vault-access authorization paths; (2) strengthening the internal security review process, including incorporating AI-assisted analysis into the review workflow; and (3) formalizing the emergency validator coordination procedure used to halt the network, so that it can be executed more systematically in future incidents. No user compensation or restitution fund was announced in publicly available reporting at the time of this investigation.","heading":"Post-Incident Response and Remediation","severity":"medium","sources":[{"credibility":1,"name":"Public Incident Report: Vault-Authorisation Vulnerability and Loss of Network Liveness | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"credibility":2,"name":"3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt | CryptoSlate","type":"news_article","url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"}]}],"sources_used":[{"credibility":1,"name":"Public Incident Report: Vault-Authorisation Vulnerability and Loss of Network Liveness | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"credibility":2,"name":"3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt | CryptoSlate","type":"news_article","url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"},{"credibility":2,"name":"3-Year-Old Bug Causes $1.3M Theft and 10-Day Radix Blockchain Halt | KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/3-year-old-bug-causes-1-3m-theft-and-10-day-radix-blockchain-halt"},{"credibility":2,"name":"A Bug Hidden Since 2023 Drained $1.3M and Froze Radix for 10 Days | CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/bug-hidden-since-2023-drained-13m-froze-radix/"},{"credibility":1,"name":"In Memory of Dan Hughes, Founder of Radix | Radix DLT Blog","type":"official","url":"https://www.radixdlt.com/blog/in-memory-of-dan-hughes-founder-of-radix"},{"credibility":2,"name":"What is Radix DLT? | Messari","type":"research","url":"https://messari.io/project/radix-dlt/profile"},{"credibility":2,"name":"Zellic — Radix Audit Reports","type":"research","url":"https://reports.zellic.io/publications/radix"},{"credibility":2,"name":"Radix (XRD) price and market cap | CoinMarketCap","type":"other","url":"https://coinmarketcap.com/currencies/radix-protocol/"},{"credibility":2,"name":"3-Year-Old Radix Bug Triggers $1.3M Theft and 10-Day Network Halt | KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/3-year-old-radix-bug-triggers-1-3m-theft-and-10-day-network-halt"},{"credibility":1,"name":"Radix Olympia Mainnet launch | Radix DLT Medium","type":"official","url":"https://radixdlt.medium.com/radix-olympia-mainnet-is-here-the-radix-blog-radix-dlt-597f63ba006"},{"credibility":1,"name":"Babylon Mainnet Upgrade Complete | Radix Ecosystem Blog","type":"official","url":"https://radixecosystem.com/news/babylon-mainnet-upgrade-complete-the-radix-blog-radix-dlt"}],"summary":"Radix (XRD) is a layer-1 blockchain protocol designed for decentralized finance, founded by Dan Hughes in 2013 and developed by RDX Works. On August 31, 2026, an attacker exploited a vault-authorization vulnerability in the Radix Engine — introduced during a June 2023 code refactor — draining approximately $1.3 million in bridged assets across 26 transactions; validators subsequently halted network consensus for 10 days until a patch was deployed on September 11, 2026. The incident represents a significant security and reliability failure for a live layer-1 network, compounded by the fact that an independent security audit in 2024 did not detect the flaw.","timeline":[{"date":"2013-05-01","event":"Dan Hughes begins developing eMunie (later renamed Radix) on Bitcointalk","source":"Messari / Radix DLT","source_url":"https://messari.io/project/radix-dlt/profile"},{"date":"2017-01-01","event":"Piers Ridyard joins as CEO; project renamed Radix; additional funding raised from Taavet Hinrikus and LocalGlobe","source":"Messari / Radix DLT","source_url":"https://messari.io/project/radix-dlt/profile"},{"date":"2021-07-28","event":"Olympia mainnet launches, introducing the Cerberus consensus protocol and XRD token","source":"Radix DLT Medium","source_url":"https://radixdlt.medium.com/radix-olympia-mainnet-is-here-the-radix-blog-radix-dlt-597f63ba006"},{"date":"2021-12-01","event":"Scrypto smart contract programming language released in preview","source":"Messari / Radix DLT","source_url":"https://messari.io/project/radix-dlt/profile"},{"date":"2023-06-01","event":"RDX Works introduces vault-authorization defect during a Radix Engine code refactoring; bug is not caught by internal review","source":"Radix DLT Public Incident Report","source_url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"date":"2023-09-28","event":"Babylon mainnet upgrade completed, enabling full smart contract execution and bringing the vulnerable Radix Engine code into production","source":"Radix Ecosystem Blog","source_url":"https://radixecosystem.com/news/babylon-mainnet-upgrade-complete-the-radix-blog-radix-dlt"},{"date":"2024-08-01","event":"Zellic conducts an independent security audit of the Radix Engine kernel; the vault-authorization vulnerability is not detected","source":"CryptoSlate / Radix DLT Public Incident Report","source_url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"},{"date":"2025-07-27","event":"Founder Dan Hughes dies unexpectedly from natural causes at his home; XRD token drops approximately 40% following the announcement","source":"Radix DLT Blog","source_url":"https://www.radixdlt.com/blog/in-memory-of-dan-hughes-founder-of-radix"},{"date":"2026-08-31","event":"Attacker executes 26 transactions between 16:02 and 16:57 UTC, draining approximately $1.3 million in bridged assets (USDC, USDT, ETH, wBTC, SOL, BNB) via the Radix Engine vault-authorization vulnerability","source":"Radix DLT Public Incident Report","source_url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"date":"2026-08-31","event":"Community validators detect unauthorized withdrawals at 17:37 UTC; Hyperlane bridge disabled by 18:09 UTC; validators coordinate to break network consensus by 23:30 UTC, halting all transaction finalization","source":"Radix DLT Public Incident Report","source_url":"https://www.radixdlt.com/blog/public-incident-report-vault-authorisation-vulnerability-2026"},{"date":"2026-09-11","event":"Radix network consensus restored after patch is deployed and independently verified by Zellic, Hacken, and SEAL 911; network had been halted for over 10 days","source":"CryptoSlate / KuCoin / CoinPaprika","source_url":"https://cryptoslate.com/3-year-old-bug-triggers-1-3-million-drain-and-forces-10-day-blockchain-halt/"}]},"v":1}