The decentralized finance ecosystem is reeling from one of the most sophisticated attacks in its history after Radiant Capital lost more than $50 million in digital assets. The breach, which occurred on October 16, 2024, involved advanced malware that compromised the hardware wallets of three long-standing developers during a routine multi-signature emissions adjustment process. As Bitcoin trades near $69,000 and Ethereum hovers around $2,746, the incident serves as a stark reminder that even the most security-conscious protocols remain vulnerable to social engineering at the developer level.
The Exploit Mechanics
According to the post-mortem published by Radiant Capital, the attacker employed highly advanced malware to poison transactions in real time. Three geographically distributed developers—all trusted, long-term contributors to the DAO—had their devices compromised simultaneously. The attackers, widely attributed to North Korean hacking groups with a track record of over $3 billion in crypto thefts between 2017 and 2023, injected malicious code that manipulated what the developers saw on their hardware wallet screens while signing what appeared to be legitimate transactions.
The attack unfolded during a standard multi-signature governance process. Each developer independently verified and signed the transaction on their hardware wallet, believing it to be a routine emissions adjustment. However, the malware intercepted the transaction data between the device interface and the signing process, replacing the intended payload with one that drained liquidity pools across both BNB Chain and Arbitrum networks. The result was a loss exceeding $50 million, including $48 million in the initial attack and an additional $5–6 million siphoned through infinite token approvals that the attackers had secretly embedded.
Affected Systems
The breach impacted Radiant Capital deployments on two major blockchain networks. On BNB Chain, attackers drained lending pools and exploited approval mechanisms to extract additional funds. On Arbitrum, similar tactics were deployed against the protocol cross-chain infrastructure. The fact that the attack vector bypassed hardware wallet security—the gold standard for crypto asset protection—has sent shockwaves through the DeFi community. Radiant had previously suffered a $4.5 million exploit in January 2024 from an unrelated vulnerability, making this the second major security incident in less than a year.
The Mitigation Strategy
In the immediate aftermath, Radiant Capital paused all protocol operations and began coordinating with blockchain security firms including Halborn and Hacken to conduct a comprehensive forensic investigation. The protocol advised all users who had interacted with Radiant contracts to revoke any outstanding token approvals as a precautionary measure. The development team also implemented emergency contract upgrades to prevent further fund extraction through the compromised approval mechanisms.
Security researchers from Hacken noted that the automated incident response systems were not adequately prepared for this type of access control attack. The attack exposed a critical gap in multi-signature security: while multi-sig protects against single points of failure, it does not inherently protect against compromised device-level signing environments.
Lessons Learned
The Radiant Capital hack demonstrates that hardware wallets alone are not sufficient to protect against sophisticated malware attacks. The industry must adopt additional verification layers, including air-gapped signing environments, multi-device verification of transaction hashes before signing, and behavioral monitoring systems that can detect anomalous transaction patterns in real time. Protocols should also consider implementing time-locked execution for high-value governance actions, providing a window for independent security review before transactions are finalized on-chain.
User Action Required
If you have interacted with Radiant Capital on either BNB Chain or Arbitrum, immediately revoke all token approvals associated with the protocol. Monitor official Radiant Capital communication channels for updates on the recovery process and any potential reimbursement plans. Consider reviewing your own security practices, particularly if you use hardware wallets for multi-signature governance roles—ensure your signing environment is free from malware by using dedicated, freshly-imaged devices for transaction verification.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals before making decisions about your digital assets.
$50M gone because malware changed what hardware wallet screens displayed. your cold storage literally lied to you while you signed. scariest attack vector in crypto
Petra M. the scariest part is the devs did everything right. they checked their screens, they used hardware wallets, they had multisig. and it still wasnt enough because the display layer itself was compromised
sig_decode_ the devs checked their screens, used hardware wallets, had geographic distribution. and it still wasnt enough because the malware poisoned the display layer. the trust model is fundamentally broken
sig_decode_ the devs did everything right: hardware wallets, multisig, geographic distribution. malware poisoning the display layer broke the entire trust model
3 devs, 3 different locations, all compromised simultaneously. that coordination level is insane. DPRK hackers are operating at nation-state tier
chain_surgeon 3 devs across different time zones hit simultaneously. that coordination points to months of reconnaissance, this wasnt opportunistic
nation-state tier coordination. DPRK has a dedicated crypto hacking unit with full government backing. protocols are fighting governments with multisig wallets
fighting governments with multisig wallets and a discord channel. the asymmetry would be funny if $50M wasnt on the line
DPRK has a dedicated bureau for this. its not hackers in hoodies, its government employees with salaries and KPIs
Anders P. DPRK bureau 121 has been running crypto theft as state policy since 2017. $3 billion tracked and thats probably half of what they actually took
blind signing is the root cause. your hardware wallet shows you a transaction hash, not what it actually does. malware exploits that gap between display and execution
blind_sig_ independent verification on a second airgapped device is the only real fix. if your signing device is compromised your verification is also compromised. never trust a single source of truth
blind_sig_ exactly. the gap between what the screen shows and what the tx actually does is where the attacker lives. blind signing should have been killed years ago
the fact that the malware changed what the hardware wallets displayed is the scariest part. you verify on screen, screen lies to you, you sign. whats the fix?
Dan K. the fix is transaction simulation on a separate device before signing. blind signing on a ledger is the vulnerability. multi-device verification should be mandatory for multisig
cold_io_ tx simulation on a separate device is the fix but nobody wants to add friction to multisig flows. convenience keeps winning over security until something blows up
Tomasz B. tx simulation on a separate device adds friction but $50M is the cost of convenience. blind signing should be dead after Radiant
whats the fix => blind signing is the problem. need a second independent verification layer, like having a separate airgapped device decode the raw tx data
the fix is independent verification on a second device. never trust the screen on the signing hardware. period.
the fix is multi-device verification independent of the signing device. a second laptop running a different tx decoder showing raw calldata
DPRK running a full department with salaries and KPIs for crypto theft while protocols defend with a 3-of-5 multisig. the asymmetry is almost comical
over $3 billion stolen by NK groups since 2017 and exchanges still cant flag the laundering fast enough. the onchain forensics improve but the thieves adapt faster
three devs in different locations compromised simultaneously and nobody thought to require tx simulation on a separate machine. $50M lesson on why multisig needs better tooling not just more signers
hardware wallet screens lying to you while you sign is the nightmare scenario. the entire trust model of cold storage depends on the display being honest
segvault_ the display being honest is the entire trust model. once malware controls what you see on the screen your hardware wallet is just a fancy paperweight with buttons
DPRK Bureau 121 running crypto theft as state policy since 2017. protocols are fighting a government agency with 3-of-5 multisig and a Discord