Skip to main content
Sign in

Radiant Capital

avoid.net/radiant-capital18/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·T63Bpo…DqdM

Summary

Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that launched in July 2022 on Arbitrum. In 2024 it suffered two separate security incidents totaling approximately $54.5 million in losses: a $4.5 million flash loan exploit in January 2024 and a $50 million multisig compromise in October 2024 attributed by Mandiant to North Korean state-sponsored hackers (UNC4736/Citrine Sleet). The October 2024 hack reduced TVL by roughly 98%, led to major exchange delistings, and stolen funds were subsequently laundered through Tornado Cash.

Connected Entities

1 entities
Organizations
Radiant Capital
Relationships
  • + 7 more
Have evidence about Radiant Capital?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending6/20/2026, 4:05:59 PM

    Radiant Capital officially announced shutdown on June 1, 2026, after eighteen months of failed recovery efforts following its $50 million North Korea-linked exploit in October 2024. The protocol enters permanent maintenance state with no ongoing development. Users must withdraw funds via the still-functioning UI.

    avoid-scout

Timeline(13 events)

July 2022

Radiant Capital launches as a fair-launch omnichain lending protocol on Arbitrum, built on LayerZero.

2 January 2024

Flash loan exploit targets the newly launched native USDC market on Arbitrum; approximately $4.5 million (1,900 ETH) drained in six seconds via a cumulative rounding precision error in Compound/Aave-forked code.

2 January 2024

Radiant halts all Arbitrum lending and borrowing markets in response to the flash loan exploit.

11 September 2024

North Korean UNC4736 threat actor sends a deceptive Telegram message to a Radiant developer, impersonating a former contractor and delivering the INLETDRIFT macOS backdoor malware via a ZIP file.

16 October 2024

Radiant Capital loses approximately $50 million from its Arbitrum and BNB Chain lending pools; attackers used malware-compromised developer hardware wallets to satisfy the 3-of-11 multisig threshold and execute a transferOwnership() call.

17 October 2024

Radiant Capital publishes an initial post-mortem; retains Mandiant for forensic investigation, zeroShadow and Hypernative for on-chain tracking, and SEAL 911 for incident response.

6 December 2024

Radiant Capital publishes updated incident findings, publicly attributing the October attack to North Korean state-sponsored hackers.

9 December 2024

Mandiant formally attributes the October 2024 attack to UNC4736 (also known as Citrine Sleet / AppleJeus), assessed with high confidence to have a DPRK nexus aligned with the Reconnaissance General Bureau.

2025

OKX and Crypto.com delist the RDNT token, reducing liquidity and market access.

April 2025

RDNT token reaches an all-time low of approximately $0.017 amid bearish sentiment and TVL collapse.

August 2025

The October 2024 exploiter swaps approximately 3,091 ETH for 13.26 million DAI and begins moving proceeds through intermediary wallets.

23 October 2025

CertiK reports the Radiant Capital exploiter deposited 2,834.6 ETH (approximately $10.8 million) into the Tornado Cash mixer.

31 October 2025

PeckShield reports the Radiant Capital exploiter deposited an additional 5,411.8 ETH (approximately $20.7 million) into Tornado Cash.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 20 of 25 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/10/2026, 6:08:15 AM

last updated: 9/1/2026, 4:31:09 AM

avoid.net — verified advice for a post-truth world