{"id":68116,"date":"2024-01-03T03:43:21","date_gmt":"2024-01-03T07:43:21","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=68116"},"modified":"2024-01-03T03:43:23","modified_gmt":"2024-01-03T07:43:23","slug":"radiant-capital-suspends-arbitrum-markets-after-flash-loan-attack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/radiant-capital-suspends-arbitrum-markets-after-flash-loan-attack\/","title":{"rendered":"Radiant Capital Suspends Arbitrum Markets After Flash Loan Attack"},"content":{"rendered":"\n<p>In response to allegations of a $4.5 million attack affecting one of its newly created <a href=\"https:\/\/coinscreed.com\/staging\/worldcoin-to-stop-usdc-payments-to-orb-operators.html\" target=\"_blank\" rel=\"noreferrer noopener\">USDC Coin<\/a> (USDC) markets, Radiant Capital has suspended its lending and borrowing markets on Arbitrum.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"936\" height=\"464\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17.png\" alt=\"Radiant Capital Suspends Arbitrum Markets After Flash Loan Attack\" class=\"wp-image-68126\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17.png 936w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17-300x149.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17-768x381.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17-18x9.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17-750x372.png 750w\" sizes=\"(max-width: 936px) 100vw, 936px\" \/><figcaption class=\"wp-element-caption\">Radiant Capital Suspends Arbitrum Markets After Flash Loan Attack<\/figcaption><\/figure>\n\n\n\n<p>&#8220;Today, we received a report of an issue with the newly created native USDC market on Arbitrum,&#8221; Radiant stated in a post on X (formerly Twitter) dated January 3. As the post continued, Radiant developers and the broader cybersecurity community confirmed the report.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Today, we received a report of an issue with the newly created native USDC market on Arbitrum.   After validation by Radiant developers and the wider Web 3 security community, the Radiant DAO Council paused lending\/borrowing markets on Arbitrum temporarily while this is\u2026<\/p>&mdash; Radiant Capital (@RDNTCapital) <a href=\"https:\/\/twitter.com\/RDNTCapital\/status\/1742338729925112272?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">January 3, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Beosin, a firm specializing in blockchain security, referred to the flaw as a &#8220;rounding error&#8221; in the codebase, &#8220;which resulted in a cumulative precision error,&#8221; thereby committing a<a href=\"https:\/\/coinscreed.com\/staging\/all-you-need-to-know-about-defi-flash-loans.html\" target=\"_blank\" rel=\"noreferrer noopener\"> flash loan attack<\/a>.<\/p>\n\n\n\n<p>This ultimately enabled the &#8220;assailant to generate profits via recurrent deposits and withdrawals,&#8221; the source wrote in a post on X on January 3.<\/p>\n\n\n\n<p>PeckShield previously characterized the issue as the result of a &#8220;known rounding issue&#8221; in the existing Compound\/Aave codebase in a January 2 post.<\/p>\n\n\n\n<p>It further stated, &#8220;The underlying cause is not novel: It exploits a time window during which a lending market's (a forked version of the popular Compound\/Aave) market becomes active.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Radiant Capital <a href=\"https:\/\/twitter.com\/RDNTCapital?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@RDNTCapital<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> was under a flash loan attack with a loss of $4.5M.<br>Attacker: <a href=\"https:\/\/t.co\/L7fXlF8VXP\" target=\"_blank\">https:\/\/t.co\/L7fXlF8VXP<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>The attacker manipulated the index parameter (which later served as a denominator) to become extremely large. The contract has a rounding issue in its\u2026 <a href=\"https:\/\/t.co\/8AdY7pjaKE\" target=\"_blank\">pic.twitter.com\/8AdY7pjaKE<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Beosin Alert (@BeosinAlert) <a href=\"https:\/\/twitter.com\/BeosinAlert\/status\/1742389285926678784?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">January 3, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Data from <a href=\"https:\/\/arbiscan.io\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Arbitrum block explorer Arbiscanner<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> indicates that the perpetrator successfully stole $4.5 million worth of Ether from the protocol.<\/p>\n\n\n\n<p>Subsequently, Radiant has suspended lending and borrowing activities on Arbitrum, assuring investors that no further funds are available at this time at risk. It secured regular operations following the conclusion of the investigation and guaranteed a comprehensive postmortem.<\/p>\n\n\n\n<p>Radiant added, &#8220;As a reminder until the markets resume trading on Arbitrum, no action can be taken.&#8221;<\/p>\n\n\n\n<p>In the interim, fraudulent Radiant Capital accounts have already inundated Crypto X with deceptive links to assist users in rescinding approvals.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-350x350\"><img decoding=\"async\" width=\"350\" height=\"350\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-16-350x350.png\" alt=\"\" class=\"wp-image-68124\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-16-350x350.png 350w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-16-150x150.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-16-75x75.png 75w\" sizes=\"(max-width: 350px) 100vw, 350px\" \/><\/figure>\n\n\n\n<p>Radiant Capital is a decentralized lending and borrowing protocol that utilizes <a href=\"https:\/\/coinscreed.com\/staging\/sequoia-ftx-a16z-lead-135m-fund-for-layerzero.html\" target=\"_blank\" rel=\"noreferrer noopener\">LayerZero technology<\/a> to enable cross-chain functionality. According to DefiLlama, the protocol presently has an estimated $300,15,000,000 locked value.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In response to allegations of a $4.5 million attack affecting one of its newly created USDC Coin (USDC) markets, Radiant Capital has suspended its lending and borrowing markets on Arbitrum. &#8220;Today, we received a report of an issue with the newly created native USDC market on Arbitrum,&#8221; Radiant stated in a post on X (formerly [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":68126,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[17742,16721,17741,1106],"class_list":["post-68116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-arbitrum-markets","tag-flash-loan-exploit","tag-radiant-capital","tag-usdc"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-17.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/68116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=68116"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/68116\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/68126"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=68116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=68116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=68116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}