Every control was present and every control held
Radiant used hardware wallets. It used multiple signers. Neither was bypassed. According to Radiant’s own account, malware on the developers’ machines caused the transaction presented for signature to differ from the transaction that executed — so each signer approved what looked like routine protocol business.
Read this next to Bybit
Four months later the Bybit cold wallet compromise followed the same pattern at thirty times the value. Two incidents, different organisations, one mechanism: the integrity of the approval step.
The industry has spent a decade hardening key storage. Both of these losses happened with the keys perfectly safe. The control that addresses this class is independent verification of the payload — decoding the raw transaction on separate infrastructure from the machine proposing it, and confirming the destination out of band. It is operationally expensive, which is why it is skipped.
Aftermath
Radiant Capital did not recover and subsequently wound down. Conisec records this as Contained rather than Resolved: the vector is closed, but users did not reach the outcome “Resolved” implies.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- Malicious transactions are approved through compromised developer devices; approximately $50m is taken. Radiant Capital
- Radiant Capital publicly describes the compromise as a sophisticated malware injection affecting multiple developers' hardware wallet signing. Radiant Capital
What to check
Radiant Capital published a detailed public statement and subsequent post-mortem; those are the authoritative record.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Radiant Capital, Public statement on the October 2024 breach (17 Oct 2024)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.