O Flash Loan Attack For Altcoin: Transactions Paused!

Radiant Capital, the cross-chain lending protocol and behind altcoin RDNT, has paused lending and lending markets on Arbitrum after receiving reports of a $4.5 million exploit affecting one of the newly created USDC Coin (USDC) markets.

Radiant Capital receives report on altcoin USDC

"Today, we received a report of a problem with the newly created native USDC market on Arbitrum," Radiant said in a Jan. 3 post on X (formerly Twitter), adding that this post was later confirmed by Radiant's developers and the broader cybersecurity community Blockchain security firm Beosin described the exploit as a flash loan attack; The attacker exploited a "bug" in the codebase to "lead to a cumulative vulnerability bug." A Jan. 3 post on X said that this ultimately "allowed the attacker to make a profit through repeated deposits and withdrawals."

Radiant Capital @RDNTCapital was under a flash loan attack with a loss of $4.5M.
Attacker:

The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its... pic.twitter.com/8AdY7pjaKE

— Beosin (@Beosin) January 3, 2024

An earlier post from PeckShield on Jan. 2 also identified the issue as stemming from a "known yulama issue" in the existing Compound/Aave codebase. "The main reason for this is not new: Basically, it takes advantage of the time window in which a new market is activated in a lending market (forked from the popular Compound/Aave)," he added. According to data from block explorer Arbiscanner, the exploiter Arbitrum managed to withdraw a total of $4.5 million in Ether from the protocol.

Operations paused

Radiant has since paused the lending and lending markets on Arbitrum, assuring investors that no additional funds are currently at risk. He promised a detailed autopsy and promised to return to normal operations once the investigation was complete. "As a reminder, no trades can be made until the pause of markets on Arbitrum is lifted," Radiant added. Meanwhile, the cryptocurrency community has already been flooded with fake Radiant Capital accounts posting phishing links that allegedly help users revoke consents.

As we reported in Kriptokoin.com, Radiant Capital is a decentralized borrowing and lending protocol with cross-chain functionality built using LayerZero technology. According to DefiLlama, the total value of the protocol is currently around $315 million. Despite the hack, the price of RNDT has risen by 2%. The cryptocurrency is currently changing hands at $0.331 levels. It had gone down to $0.0308 during the day. Time will tell whether it will be affected by the hacking news in the coming period.

Follow us on Twitter*, Facebook and Instagram to stay up to date with breaking news. Join our Telegram and Youtube channel.*

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)