lazarusholic

Everyday is lazarus.dayβ

Radiant Capital Hack Analysis

2024-05-17, QuillAudits
https://www.quillaudits.com/blog/hack-analysis/radiant-capital-hack
#RadiantCapital

Contents

On January 3, 2024, Radiant Capital, a cross-chain lending protocol on Arbitrum, was exploited for approximately $4.5 million worth of ETH. The hack primarily resulted from vulnerabilities in the smart contract code and leveraged existing rounding issues in the codebase.
Radiant Capital (RDNT) is a decentralized finance (DeFi) project that aims to consolidate fragmented liquidity across multiple lending protocols and chains. For more information, check out their website.
Attacker Address :- 0x826d5f4d8084980366f975e10db6c4cf1f9dde6d
Attack Contract:- 0x39519c027b503f40867548Fb0c890b11728faA8F
Vulnerable Contract:- 0xF4B1486DD74D07706052A33d31d7c0AAFD0659E1
Attack Transaction:-0x1ce7e9a9e3b6dd3293c9067221ac3260858ce119ecb7ca860eac28b2474c7c9b
The root cause of the incident with the Radiant Capital project was a flaw in the way they calculated token quantities. This calculation involved two main elements: precision expansion and rounding. Here’s a simplified explanation of both the root cause and how the vulnerability was exploited:
Ready to secure your Arbitrum Smart Contracts? Take the first step towards a safer blockchain journey. Request an Audit with QuillAudits today & ensure your contracts are robust and secure!
1. To …

IoC

826d5f4d8084980366f975e10db6c4cf1f9dde6d
1ce7e9a9e3b6dd3293c9067221ac3260858ce119ecb7ca860eac28b2474c7c9b
39519c027b503f40867548Fb0c890b11728faA8F
F4B1486DD74D07706052A33d31d7c0AAFD0659E1