Skip to content
Incident record

Radiant Capital Signing Compromise, October 2024: What Happened & What to Check

Malware on three developers' devices produced hardware-wallet approvals that looked legitimate, taking roughly $50m.

Contained Discovered Disclosed
Share X in @
Schematic of the Radiant Capital incident showing the key compromise stage as the failure point.
Schematic of the Radiant Capital incident showing the key compromise stage as the failure point.

At a glance

AFFECTED ENTITY
Radiant Capital
CHAIN(S)
Arbitrum, BNB Chain
REPORTED LOSS
approx. US$50 million(Radiant Capital, 17 Oct 2024)
OFFICIAL RESPONSE
x.com

Every control was present and every control held

Radiant used hardware wallets. It used multiple signers. Neither was bypassed. According to Radiant’s own account, malware on the developers’ machines caused the transaction presented for signature to differ from the transaction that executed — so each signer approved what looked like routine protocol business.

Read this next to Bybit

Four months later the Bybit cold wallet compromise followed the same pattern at thirty times the value. Two incidents, different organisations, one mechanism: the integrity of the approval step.

The industry has spent a decade hardening key storage. Both of these losses happened with the keys perfectly safe. The control that addresses this class is independent verification of the payload — decoding the raw transaction on separate infrastructure from the machine proposing it, and confirming the destination out of band. It is operationally expensive, which is why it is skipped.

Aftermath

Radiant Capital did not recover and subsequently wound down. Conisec records this as Contained rather than Resolved: the vector is closed, but users did not reach the outcome “Resolved” implies.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Malicious transactions are approved through compromised developer devices; approximately $50m is taken. Radiant Capital
  2. Radiant Capital publicly describes the compromise as a sophisticated malware injection affecting multiple developers' hardware wallet signing. Radiant Capital

What to check

Radiant Capital published a detailed public statement and subsequent post-mortem; those are the authoritative record.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Radiant Capital, Public statement on the October 2024 breach (17 Oct 2024)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.