Six-Second Flash Loan Exploit Drains $4.5M from Radiant Capital's New Arbitrum Market
Radiant Capital, a lending protocol forked from Aave V2 that runs on Arbitrum and BNB Smart Chain, lost 1,900 ETH (about $4.5 million) to an exploit targeting a previously known class of bug affecting newly launched markets. The attack hit the Arbitrum deployment's freshly added native USDC market.

Evidence suggests the attacker had been watching for this opportunity for some time, likely having spotted the underlying vulnerability in Aave forks through updates made to the original Aave protocol. Word of the incident spread on Twitter/X after the attacker's address and related Discord screenshots were shared publicly. Radiant Capital later issued an official statement asserting that "no current funds are at risk" — despite the roughly $4.5 million already lost by that point. Credit for surfacing details of the incident goes to Peckshield and Ancilia.
The underlying issue affects Aave V2 forks generally: a newly launched market sits empty immediately after deployment, and the combination of a rounding error with a totalSupply value of zero gives an attacker a narrow window to use a flash loan to manipulate that market's collateral valuation. In Radiant's case, the attacker deployed their attack contract just six seconds after the new market was activated — a speed that indicates thorough preparation in advance, most likely during the wait for the governance proposal to add the market, which had passed on Snapshot on December 25th, to actually be enacted. The original Aave protocol had already mitigated this class of bug by requiring an initial deposit whenever a new market is created, so that it is never left empty — a safeguard that was apparently not carried over in Radiant's fork.
Key on-chain identifiers from the incident:
- Attacker address: 0x826d5f4d8084980366f975e10db6c4cf1f9dde6d
- Attack contract: 0x39519c027b503f40867548fb0c890b11728faa8f
- Attack transaction 1: 0x1ce7e9a9e3b6dd3293c9067221ac3260858ce119ecb7ca860eac28b2474c7c9b
- Attack transaction 2: 0x2af556386c023f7ebe7c662fd5d1c6cc5ed7fba4723cbd75e00faaa98cd14243
- Attack transaction 3: 0xc5c4bbddec70edb58efba60c1f27bce6515a45ffcab4236026a5eeb3e877fc6d
Radiant's team subsequently sent an on-chain message to the attacker's address, where the funds have remained, and indicated they believe — for reasons not fully disclosed — that they may be dealing with a whitehat rather than a malicious actor.
Radiant Capital had undergone four separate audits, from OpenZeppelin, BlockSec, PeckShield, and Zokyo, underscoring how a shifting security landscape can still leave forked code exposed if updates aren't applied promptly. This is far from the first time a forked protocol has been caught out this way: prior leaderboard entries have repeatedly involved vulnerabilities that were patched in an original codebase well before being exploited in a downstream fork, since forks generally draw less security scrutiny than the higher-TVL projects they copy. Whether other Aave-fork teams currently planning to launch new markets have internalized this risk, as some have urged, remains an open question.

Get new scam files the moment we publish them — usually 2–3 emails a week.