Radiant Capital
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·T63Bpo…DqdMSummary
Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that launched in July 2022 on Arbitrum. In 2024 it suffered two separate security incidents totaling approximately $54.5 million in losses: a $4.5 million flash loan exploit in January 2024 and a $50 million multisig compromise in October 2024 attributed by Mandiant to North Korean state-sponsored hackers (UNC4736/Citrine Sleet). The October 2024 hack reduced TVL by roughly 98%, led to major exchange delistings, and stolen funds were subsequently laundered through Tornado Cash.
Connected Entities
1 entities- + 7 more
Community submissions
- Under reviewincriminatingWayback pending6/20/2026, 4:05:59 PM
“Radiant Capital officially announced shutdown on June 1, 2026, after eighteen months of failed recovery efforts following its $50 million North Korea-linked exploit in October 2024. The protocol enters permanent maintenance state with no ongoing development. Users must withdraw funds via the still-functioning UI.”
— avoid-scout
Timeline(13 events)
July 2022
Radiant Capital launches as a fair-launch omnichain lending protocol on Arbitrum, built on LayerZero.
2 January 2024
Flash loan exploit targets the newly launched native USDC market on Arbitrum; approximately $4.5 million (1,900 ETH) drained in six seconds via a cumulative rounding precision error in Compound/Aave-forked code.
2 January 2024
Radiant halts all Arbitrum lending and borrowing markets in response to the flash loan exploit.
11 September 2024
North Korean UNC4736 threat actor sends a deceptive Telegram message to a Radiant developer, impersonating a former contractor and delivering the INLETDRIFT macOS backdoor malware via a ZIP file.
16 October 2024
Radiant Capital loses approximately $50 million from its Arbitrum and BNB Chain lending pools; attackers used malware-compromised developer hardware wallets to satisfy the 3-of-11 multisig threshold and execute a transferOwnership() call.
17 October 2024
Radiant Capital publishes an initial post-mortem; retains Mandiant for forensic investigation, zeroShadow and Hypernative for on-chain tracking, and SEAL 911 for incident response.
6 December 2024
Radiant Capital publishes updated incident findings, publicly attributing the October attack to North Korean state-sponsored hackers.
9 December 2024
Mandiant formally attributes the October 2024 attack to UNC4736 (also known as Citrine Sleet / AppleJeus), assessed with high confidence to have a DPRK nexus aligned with the Reconnaissance General Bureau.
2025
OKX and Crypto.com delist the RDNT token, reducing liquidity and market access.
April 2025
RDNT token reaches an all-time low of approximately $0.017 amid bearish sentiment and TVL collapse.
August 2025
The October 2024 exploiter swaps approximately 3,091 ETH for 13.26 million DAI and begins moving proceeds through intermediary wallets.
23 October 2025
CertiK reports the Radiant Capital exploiter deposited 2,834.6 ETH (approximately $10.8 million) into the Tornado Cash mixer.
31 October 2025
PeckShield reports the Radiant Capital exploiter deposited an additional 5,411.8 ETH (approximately $20.7 million) into Tornado Cash.
Decision Log
- hash: D2xs87LZoSH5MxQfJmsBrGfsh2wzQa6sK3jeMfxkcA3J
- hash: 7tg6XDFjpwQs8yLFWQjcokuh7aArpT6NWqmTKaVA4FJ3
- hash: 9Bz3h16rCAhn9Ya1TPFTkW31WTFGFyvSZqd8RMESR5zQ
This investigation is cryptographically anchored to the Solana blockchain (3 events). 20 of 25 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/10/2026, 6:08:15 AM
last updated: 9/1/2026, 4:31:09 AM
avoid.net — verified advice for a post-truth world