Case summary
What happened
On 2024-01-02, Radiant's newly launched native USDC market on Arbitrum was exploited through a flash-loan/loss-of-precision mechanism, resulting in unauthorized borrowing of approximately 1,900 WETH and communal bad debt that the DAO later recapitalized. On 2024-10-16, a separate compromise of the protocol's multisig signing process enabled attackers to drain approximately USD 50 million from core markets on Arbitrum and BNB Chain and abuse open user approvals. Recovery and remediation efforts continued into 2026. On 2026-06-01, Radiant announced an orderly wind-down: active development ceased, borrowing was disabled across Core and RIZv1 markets, RDNT emissions were discontinued, and the protocol shifted to maintenance, withdrawals/repayments, user support and recovery work.
Customer result
Customer outcome
Claims ongoing
The January 2024 communal bad debt was addressed through DAO/OpEx recapitalization under RFP-27, but that is separate from the October 2024 user-loss remediation process. Radiant's June 2026 wind-down notice states that affected October 2024 users had not been remediated through recovered exploit funds, that no meaningful recovery had been obtained via zeroShadow, and that the remediation portal and claims infrastructure would remain available. Any future recovered funds are intended for affected users. No universal realized recovery percentage is asserted.
- Estimated recovery
- Unknown
- Repayment started
- —
- Repayment completed
- —
- Confidence
- High
Asset treatment
Terms risk
Customer-owned
Radiant is modeled as non-custodial DeFi lending rather than a platform-owned account balance. The October 2024 incident nevertheless demonstrates material administrative-control and approval risk: compromised multisig signing enabled hostile contract control, and open-ended token approvals allowed additional unauthorized transfers from user wallets. The June 2026 wind-down further limits new borrowing while preserving user-directed withdrawals, repayments and position management.
- Affected product
- —
- Confidence
- High
Known unknowns
Uncertainty
Radiant's June 2026 announcement explicitly says the protocol is not being shut down immediately: front-end functionality, immutable contracts, position management and remediation/recovery support remain. CYA therefore uses status=limited rather than operations_ended. No universal realized recovery percentage is asserted for users affected by the October 2024 exploit.
Chronology
Historical record
Radiant Arbitrum native USDC market exploit creates approximately 1,900 WETH bad debt
Radiant Capital's newly introduced native USDC market on Arbitrum was exploited through a flash-loan/loss-of-precision attack that manipulated the liquidityIndex while reserves were effectively empty. The attacker borrowed approximately 1,900 WETH. Radiant paused lending pools, later resumed unaffected markets, and used DAO/OpEx resources under RFP-27 to recapitalize the resulting communal bad debt.
The approximately USD 4.5 million value is a contemporaneous valuation of roughly 1,900 ETH/WETH and is distinct from the later October 2024 exploit. DAO repayment of communal bad debt is not treated as evidence about outcomes of the October incident.
Radiant multisig compromise drains approximately USD 50 million from Arbitrum and BNB Chain markets
A targeted compromise of Radiant Capital's multisig signing workflow enabled attackers to obtain malicious signatures and take control of core lending contracts on Arbitrum and BNB Chain. Approximately USD 50 million was drained from core markets, and open-ended user token approvals were also abused to withdraw assets from user wallets. Recovery, tracking and remediation efforts followed, but Radiant later reported that affected users had not been fully remediated and that exploited funds remained unrecovered.
Official Radiant materials describe approximately USD 50M or USD 50M+; CYA records USD 50M as a conservative event metric and does not infer a universal final customer-loss figure.
Radiant DAO begins orderly wind-down and shifts protocol to maintenance and recovery mode
After prolonged post-exploit recovery efforts failed to restore a viable operating runway, Radiant Capital DAO announced an orderly wind-down. Active development stopped, borrowing was disabled across Core and RIZv1 markets by setting caps to 1, RDNT emissions were discontinued, and treasury usage was restricted to essential operations. The protocol was not immediately shut down: the front end, immutable contracts, withdrawals, repayments, position management, remediation portal and recovery work were retained in a reduced maintenance state.
This is a wind-down transition rather than completed operations_ended. CYA should revisit the record after the announced front-end support window and if recovery/remediation infrastructure changes materially.
Source record
Evidence dossier
Filter by claim, reliability, source type, and whether evidence is linked to a specific event.
customer outcome
1 sourcesRadiant Capital DAO Community Remediation Plan
Radiant Capital · 2025-07-07
First-party remediation timeline and plan for users affected by the October 2024 exploit, including balance-checking and remediation infrastructure.
Event
5 sourcesPost-Mortem Report: Radiant Capital
Radiant Capital · 2024-01-19
First-party post-mortem for the 2024-01-02 Arbitrum native USDC exploit. It describes liquidityIndex manipulation, approximately 1,900 WETH unauthorized borrowing, emergency pauses, market resumption and the RFP-27 bad-debt repayment path.
Radiant Capital reportedly hacked for $4.5 million worth of ETH
The Block · 2024-01-02
Independent contemporary corroboration of the roughly 1,900 ETH / USD 4.5 million January 2024 incident and temporary Arbitrum lending/borrowing suspension.
Radiant Post-Mortem
Radiant Capital · 2024-10-18
First-party post-mortem describing compromise of the multisig signing process, approximately USD 50 million drained from Arbitrum and BSC/BNB Chain core markets, abuse of open approvals and plans to redeploy the Aave V2 lending suite.
Radiant Capital Incident Update
Radiant Capital · 2024-12-06
First-party incident update describing an approximately USD 50 million loss and the Mandiant-assisted investigation into the targeted cyberattack.
Radiant Capital appears to suffer $51 million exploit on its BNB Chain and Arbitrum instances
The Block · 2024-10-16
Independent contemporary reporting corroborating the Arbitrum and BNB Chain scope and approximately USD 51 million observed loss estimate.
status
2 sourcesSunsetting Radiant Capital DAO: Entering Recovery Phase and Lessons for the Future of DeFi
Radiant Capital · 2026-06-01
First-party wind-down announcement: active development ceased, borrowing disabled, emissions discontinued, while the website, withdrawals, repayments, position management, remediation portal and recovery work remained available in reduced maintenance mode.
Unable to recover from roughly $50 million hack, Radiant Capital is winding down
The Block · 2026-06-01
Independent reporting corroborating Radiant's maintenance-state wind-down while front-end access, withdrawals, repayments and position management remain available.
No evidence records match the current filters.
Comparative records