Connect with us

Hi, what are you looking for?

Radiant capital
Radiant capital

Business

Radiant Capital loses $50 million to a sophisticated North Korean cyberattack

North Korean hackers, posing as a former contractor, carried out a $50 million hack, as Radiant Capital announced in October. The attackers exploited malware embedded in a shared file to compromise developer devices and circumvent advanced security safeguards.

Radiant Capital, a decentralized finance platform, has acknowledged that a North Korean hacking squad was responsible for a $50 million system breach in October. The attackers impersonated a trusted former contractor and supplied malware disguised as a valid document, taking advantage of professional communication standards.

The attack started on September 11 when a Radiant developer received a Telegram message from someone pretending to be a former contractor. The communication contained a zip file masquerading as a request for comments on a new project. After sharing the file with additional developers, the imbedded malware infected many devices.

This infection allowed hackers to access private keys and smart contracts, leading to the October 16 vulnerability that forced the platform to halt its lending activities. Mandiant, Radiant’s cybersecurity partner, linked the attack to a North Korean entity named “UNC4736,” likely associated with the Lazarus entity.

The platform reported that the virus was sophisticated, operating undetected by mimicking normal functionality and carrying out harmful operations in the background. This deceit rendered the compromise unnoticed during routine security assessments, including those performed with advanced technologies such as Tenderly.

Radiant Capital admitted that, despite strict security mechanisms, such as the use of hardware wallets and transaction simulations, the attackers were able to defeat these safeguards. The breach emphasizes the critical need for more robust hardware-based solutions to validate transactions on a deeper level.

The attackers relocated the stolen cash, worth an estimated $52 million, on October 24. This is the second large attack on Radiant Capital this year, after a $4.5 million vulnerability in January. The platform’s total value locked in (TVL) has since dropped from more than $300 million to under $5.81 million.

Radiant’s experience highlights the growing threat of complex assaults on DeFi platforms, as well as the significance of constant innovation in security practices.

author avatar
Satpal S
Satpal is an Editor and Author at 4C Media Co, specializing in all stories and news related to crypto and finance.
Advertisement

You May Also Like

Business

This week marked a defining moment for institutional crypto adoption. Bank of America brought Bitcoin ETFs into everyday wealth management, Morgan Stanley filed for...

Business

Binance gold and silver perpetual futures are now live, allowing traders to gain 24/7 exposure to precious metals via USDT-settled contracts—marking a bold step...

Cryptocurrency

Dubai has issued an important update on crypto token regulation policy. The Dubai Financial Services Authority (DFSA) is transferring responsibility for carrying out crypto...

Business

Tennessee regulators have given Kalshi, Polymarket and Crypto.com a writ to stop offering contracts linked to sports betting, cancel all existing bets and refund...

polkadot
Polkadot (DOT) $ 2.20 3.67%
bitcoin
Bitcoin (BTC) $ 96,581.00 1.80%
ethereum
Ethereum (ETH) $ 3,328.87 0.01%
cardano
Cardano (ADA) $ 0.404288 4.53%
xrp
XRP (XRP) $ 2.10 1.88%
stellar
Stellar (XLM) $ 0.231294 4.91%
litecoin
Litecoin (LTC) $ 74.62 5.72%