CryptoReal
CASE FILE — Oct 17, 2024

Compromised Signers Let Attacker Loot $53M From Radiant Capital's Multi-Chain Markets

Radiant Capital, the multi-chain lending protocol, suffered its second major security incident of 2024 on October 17 when an attacker drained more than $53 million from user deposits after taking control of the project's multi-signature wallet.

The earlier incident this year was a $4.5 million flash loan exploit, making this the protocol's second serious breach in a matter of months.

01How the breach was detected

Security firm Ancilia flagged unusual activity on Radiant's BSC deployment, estimating that roughly $16 million had already been siphoned off, and urged holders to revoke contract approvals immediately. Radiant took about two hours to publicly confirm that both its BSC and Arbitrum markets had been compromised. The team said it was working with outside security firms and moved to pause its Base and Ethereum mainnet markets as a precaution.

Radiant urged users to revoke approvals for the following contracts:

02A multisig with too low a bar

Radiant's operational security rested on an 11-signer multisig, a configuration that on paper looked resilient. In practice, only three signatures were needed to push through a transaction, and it was exactly that low quorum that gave the attacker their opening. Whoever carried out the exploit had gained control over at least three of the eleven signing keys.

With that access secured, the attacker followed a three-step playbook:

  1. Transfer ownership of the lending pools to a contract they controlled.
  2. Push a malicious implementation upgrade to the pools.
  3. Withdraw funds from the now-compromised pools.

03Weeks of groundwork before the strike

Sums referenced in this case file

The takeover targeted the Pool Provider contract — the piece of infrastructure that governs Radiant's various lending markets — transferring its ownership to a malicious contract on both BSC and Arbitrum.

Relevant transactions and addresses:

Stolen assets were routed through 1inch, ParaSwap, PancakeSwap, and Odos to convert holdings into ETH and BNB, then forwarded to:

The contract used as the malicious upgrade implementation had actually been deployed 14 days before the attack across several chains:

That two-week gap between deployment and execution points to a deliberately staged operation rather than an opportunistic strike. Data surfaced by Hacken also shows the attacker made an earlier, unsuccessful attempt on Arbitrum six days before the successful one:

That failed run suggests the attacker was refining their method rather than giving up after the first setback. Copies of the same malicious contract were also deployed on Ethereum and Base, though they were never triggered:

The presence of dormant contracts on those two additional chains indicates the attacker may have planned a broader, four-chain operation that never fully materialized before Radiant caught on.

04Aftermath

With more than $53 million gone, Radiant Capital now faces its second severe reputational and financial hit of the year, raising questions about whether a 3-of-11 signature threshold was ever an adequate safeguard for a protocol operating across multiple chains. The episode underscores how a multisig's nominal signer count means little if the execution threshold is set low enough for a handful of compromised keys to move the whole treasury.

ForkRadiant Capital
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.