Radiant Capital Loses 1,900 ETH In Hack
In a major hacking incident, the cross-chain lending protocol Radiant Capital suffered a loss of 1,900 ETH, equivalent to $4.5 million. The breach occurred during the activation of a new market on the platform, which was built from popular platforms Compound/Aave. The attacker exploited a known rounding issue in the codebase and executed the exploit just 6 seconds after the new USDC market was activated.
Preventing Exploits
To prevent similar exploits, blockchain security firm PeckShield suggests implementing a simple solution: ensuring that when a new market is added, it is activated with a Collateral Factor (CF) of 0%. This would provide an additional layer of security against such attacks.
Pausing Lending/Borrowing Activity
Radiant Capital has temporarily halted lending and borrowing markets on Arbitrum, where the incident occurred. This pause in activity allows for a thorough investigation to take place. It is important to note that no existing funds are currently at risk. Once the investigation is complete and the issue is resolved, regular protocol operations will resume.
Continued Security Breaches in the Crypto Market
The hacking incident at Radiant Capital adds to the growing list of security breaches in the crypto market. Just recently, Orbit Bridge experienced an outflow of $81.5 million across multiple cryptocurrencies, raising concerns about a significant security breach. The attacker in this case potentially compromised multi-signature signers and used funds from TornadoCash to carry out the attack.
Hot Take: Heightened Concerns Over Crypto Security
The recent hacking incidents at Radiant Capital and Orbit Bridge highlight the ongoing vulnerabilities and risks associated with the crypto market. These breaches not only result in substantial financial losses but also erode investor confidence. As we enter 2024, it is crucial for crypto platforms and protocols to prioritize security measures and implement robust solutions to mitigate the potential for exploits. The development of safer codebases, regular security audits, and proactive measures against known vulnerabilities are essential to protect user funds and maintain trust within the industry.