Radix says validators halted consensus after exploit drained third-party vault assets

Radix says validators halted consensus after exploit drained third-party vault assets

N
News Editor
2026-09-19 01:10:00
Radix Foundation said in an incident report that an attacker exploited a previously undiscovered flaw in the Radix Engine to withdraw assets from third-party vaults without owner authorization. The stolen funds were then bridged through Hyperlane to other networks, including Ethereum, BNB Chain and Solana, where they were sold. According to the report, the bug traced back to a code cleanup in June 2023. Radix added that an independent security audit conducted by Zellic in August 2024 did not identify the issue. Roughly three hours after the incident began, Radix validators intentionally took enough stake offline to prevent the network from continuing to reach consensus, a move the foundation said stopped further exploitation. Assets affected in the incident included ETH, WBTC, USDT, USDC, BNB and SOL. Radix said the vulnerability has now been fixed, and that the patch has undergone independent review and testing. The network recovery process is currently underway.

Radix Foundation said in an incident report that an attacker used a previously undiscovered vulnerability in the Radix Engine to withdraw assets from third-party vaults without the owners’ authorization. The assets were then bridged through Hyperlane to networks including Ethereum, BNB Chain and Solana, where they were sold.

Bug traced to 2023 code cleanup

The foundation said the vulnerability originated from a code cleanup carried out in June 2023. It also said an independent security audit performed by Zellic in August 2024 did not detect the issue.

Validators took stake offline to stop further abuse

About three hours after the incident began, Radix validators proactively took enough stake offline to prevent the network from continuing to reach consensus. According to the report, that step stopped the exploit from being used further. Affected assets included ETH, WBTC, USDT, USDC, BNB and SOL.

Radix said the vulnerability has been fixed and that the remediation work has gone through independent review and testing. The network is now moving through the recovery process.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.