Radiant Capital Hack: How a Fake PDF Led to $50 Million Theft in 3 Minutes

Radiant Capital Hack: How a Fake PDF Led to $50 Million Theft in 3 Minutes

N
News Editor 01
2026-07-08 17:50:16
Radiant Capital lost $50 million in a sophisticated cyberattack linked to North Korean hackers. A fake PDF file containing malware tricked developers, exploiting blind signing on Ledger wallets. The entire heist took under 3 minutes.
blockchain securityDeFihackRadiant CapitalNorth Korea

On October 16, 2024, Radiant Capital, a decentralized cross-chain lending protocol built on Layerzero, suffered a devastating breach that resulted in the theft of approximately $50 million. The attack sent shockwaves through the DeFi community, with security experts like @bantg calling it “really scary” and noting that the compromised signers had followed best practices. Investigators later linked the hack to North Korean threat actors.

The Entry Point: A Telegram Message Disguised as a Job Inquiry

The attack chain began on September 11, when a Radiant Capital developer received a Telegram message from someone impersonating a trusted former contractor. The fake message claimed the contractor was seeking a new opportunity in smart contract auditing and requested feedback on a compressed PDF containing details of their next assignment. The hackers even mimicked the contractor’s legitimate website to add credibility.

However, the zip file contained a disguised executable named INLETDRIFT. Upon opening, the malware infected the developer’s macOS device, establishing communication with a hacker-controlled server. Tragically, the compromised file was shared with other team members for feedback, spreading the malware further across the organization.

Exploiting Blind Signing: The Critical Blow

Using the implanted backdoor, the attackers executed a man-in-the-middle (MITM) attack. While Radiant’s team relied on Gnosis Safe multisig wallets for security, the malware intercepted and manipulated transaction data in real time. On developers’ screens, transactions appeared legitimate, but in reality, the hackers replaced them with malicious instructions targeting ownership of lending pool contracts.

The attackers then exploited a blind signing vulnerability in Ledger hardware wallets. Because hardware wallets often lack detailed transaction summaries, developers unknowingly signed a transferOwnership() call, handing over control of Radiant’s funds. In under three minutes, the hackers drained the assets, removed backdoors, and erased all traces of their activities, leaving investigators with minimal forensic evidence.

Industry Lessons: Strengthening DeFi Security

This breach highlights the growing sophistication of cyber threats. Key takeaways include:

  • Avoid unverified downloads: Teams should strictly avoid downloading files from external or untrusted sources, especially compressed archives.
  • Front-end verification is vulnerable to spoofing: Projects should adopt advanced verification tools and supply chain monitoring to detect tampering.
  • Hardware wallet blind signing risks: Enhanced support for multi-sig transactions with detailed summaries could mitigate this issue.
  • Implement timelocks and governance frameworks: Delaying critical fund transfers allows teams to identify and respond to anomalies before assets are lost.

Radiant DAO continues to cooperate with Mandiant, Zeroshadow, and U.S. law enforcement in an effort to freeze stolen assets. The protocol has expressed its commitment to sharing the lessons learned to help raise security standards across the entire DeFi industry. This incident serves as a stark reminder that as the DeFi ecosystem grows, attackers’ ingenuity grows with it—only constant vigilance and robust security protocols can protect users’ funds.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.