Skip to main content
Sign in

Radiant V2

avoid.net/radiant-v210/100·100% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·39AwoP…kKyt

Summary

Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that suffered two significant security incidents in 2024: a $4.5 million flash loan exploit in January 2024 and a far more devastating $50 million multisig compromise in October 2024. The October hack, attributed by Mandiant with high confidence to North Korean state-sponsored group UNC4736 (Citrine Sleet / AppleJeus), involved a months-long social engineering campaign, macOS malware deployment on developer devices, and manipulation of hardware wallet signing interfaces to drain funds across BNB Chain and Arbitrum.

Connected Entities

1 entities
Organizations
Radiant V2
Relationships
  • + 1 more
Have evidence about Radiant V2?

Timeline(11 events)

July 2022

Radiant Capital launches RDNT token on Arbitrum via Sushiswap fair launch.

2 January 2024

Flash loan exploit drains $4.5 million ETH from newly activated USDC market on Arbitrum via rounding error in liquidityIndex calculation.

3 January 2024

Radiant pauses Arbitrum lending and borrowing markets; promises post-mortem and user repayment.

11 September 2024

North Korean UNC4736 attacker sends malicious Telegram message to Radiant developer, impersonating a former contractor; INLETDRIFT macOS malware deployed via ZIP file.

16 October 2024

Attackers exploit compromised hardware wallets of at least 3 of 11 multisig signers to execute transferOwnership() on LendingPoolAddressesProvider; approximately $50–53 million drained from BSC and Arbitrum markets. Backdoor removed within 3 minutes of theft.

17 October 2024

Radiant publishes initial post-mortem; engages Mandiant, zeroShadow, Hypernative, and SEAL 911.

24 October 2024

On-chain tracking confirms hacker bridges $52M in stolen funds to Ethereum.

6 December 2024

Radiant Capital publishes updated incident report attributing attack to UNC4736 (North Korea) based on Mandiant forensic analysis.

9 December 2024

Public attribution of attack to DPRK-linked UNC4736 / Citrine Sleet / AppleJeus group reported by major media.

August 2025

On-chain monitors observe hacker actively trading stolen ETH and DAI; stolen portfolio value reportedly grows from $53M to over $94M through ETH appreciation and active arbitrage.

October 2025

Hacker deposits 2,834.6 ETH (approximately $10.8M) into sanctioned mixer Tornado Cash, substantially reducing recovery prospects.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 19 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:36 AM

last updated: 9/1/2026, 7:15:37 AM

avoid.net — verified advice for a post-truth world