Compromised Signers Let Attacker Loot $53M From Radiant Capital's Multi-Chain Markets
Radiant Capital, the multi-chain lending protocol, suffered its second major security incident of 2024 on October 17 when an attacker drained more than $53 million from user deposits after taking control of the project's multi-signature wallet.
The earlier incident this year was a $4.5 million flash loan exploit, making this the protocol's second serious breach in a matter of months.

01How the breach was detected
Security firm Ancilia flagged unusual activity on Radiant's BSC deployment, estimating that roughly $16 million had already been siphoned off, and urged holders to revoke contract approvals immediately. Radiant took about two hours to publicly confirm that both its BSC and Arbitrum markets had been compromised. The team said it was working with outside security firms and moved to pause its Base and Ethereum mainnet markets as a precaution.
Radiant urged users to revoke approvals for the following contracts:
- Arbitrum: 0xF4B1486DD74D07706052A33d31d7c0AAFD0659E1
- BSC: 0xd50Cf00b6e600Dd036Ba8eF475677d816d6c4281
- Base: 0x30798cFe2CCa822321ceed7e6085e633aAbC492F
- Ethereum: 0xA950974f64aA33f27F6C5e017eEE93BF7588ED07
02A multisig with too low a bar
Radiant's operational security rested on an 11-signer multisig, a configuration that on paper looked resilient. In practice, only three signatures were needed to push through a transaction, and it was exactly that low quorum that gave the attacker their opening. Whoever carried out the exploit had gained control over at least three of the eleven signing keys.
With that access secured, the attacker followed a three-step playbook:
- Transfer ownership of the lending pools to a contract they controlled.
- Push a malicious implementation upgrade to the pools.
- Withdraw funds from the now-compromised pools.
03Weeks of groundwork before the strike
The takeover targeted the Pool Provider contract — the piece of infrastructure that governs Radiant's various lending markets — transferring its ownership to a malicious contract on both BSC and Arbitrum.
Relevant transactions and addresses:
- Attack transaction (BSC): 0xd97b93f633aee356d992b49193e60a571b8c466bf46aaf072368f975dc11841c
- Attack transaction (Arbitrum): 0x7856552db409fe51e17339ab1e0e1ce9c85d68bf0f4de4c110fc4e372ea02fb1
- Attacker address (BSC): 0x0629b1048298AE9deff0F4100A31967Fb3f98962
- Attacker address (Arbitrum): 0x97a05becc2e7891d07f382457cd5d57fd242e4e8
Stolen assets were routed through 1inch, ParaSwap, PancakeSwap, and Odos to convert holdings into ETH and BNB, then forwarded to:
- Destination address (Arbitrum): 0x8B75E47976C3C500D0148463931717001F620887
- Destination address (BSC): 0xcF47c058CC4818CE90f9315B478EB2f2d588Cc78
The contract used as the malicious upgrade implementation had actually been deployed 14 days before the attack across several chains:
- Malicious contract (BSC): 0x57ba8957ed2ff2e7AE38F4935451E81Ce1eEFbf5
- Malicious contract (Arbitrum): 0x57ba8957ed2ff2e7AE38F4935451E81Ce1eEFbf5
That two-week gap between deployment and execution points to a deliberately staged operation rather than an opportunistic strike. Data surfaced by Hacken also shows the attacker made an earlier, unsuccessful attempt on Arbitrum six days before the successful one:

- Failed attack transaction (Arbitrum): 0xab34055320676b35d4c6c5936dabc4101b45eda0d66b94ee02f10a96e8a1dd45
That failed run suggests the attacker was refining their method rather than giving up after the first setback. Copies of the same malicious contract were also deployed on Ethereum and Base, though they were never triggered:
- Malicious contract (Ethereum): 0x3C2Bc83Dcd293Cc8a23526A37aaeEdD83eBd62de
- Malicious contract (Base): 0x57ba8957ed2ff2e7AE38F4935451E81Ce1eEFbf5
The presence of dormant contracts on those two additional chains indicates the attacker may have planned a broader, four-chain operation that never fully materialized before Radiant caught on.
04Aftermath
With more than $53 million gone, Radiant Capital now faces its second severe reputational and financial hit of the year, raising questions about whether a 3-of-11 signature threshold was ever an adequate safeguard for a protocol operating across multiple chains. The episode underscores how a multisig's nominal signer count means little if the execution threshold is set low enough for a handful of compromised keys to move the whole treasury.
Get new scam files the moment we publish them — usually 2–3 emails a week.