defi lending · Global

Radiant Capital

Omnichain non-custodial DeFi lending protocol that suffered two major security incidents in 2024 and entered an orderly maintenance-mode wind-down in 2026. Users retain access to withdraw, repay and manage positions while active development and new borrowing have ceased and recovery/remediation infrastructure remains in place.

Also known as: Radiant, Radiant Capital DAO, RDNT

Status
Limited
Outcome
Claims ongoing
Confidence
High
Last verified
2026-09-01
Launch
End
Failure reasonVoluntary shutdown
Events3
Evidence8
Products1

Case summary

What happened

On 2024-01-02, Radiant's newly launched native USDC market on Arbitrum was exploited through a flash-loan/loss-of-precision mechanism, resulting in unauthorized borrowing of approximately 1,900 WETH and communal bad debt that the DAO later recapitalized. On 2024-10-16, a separate compromise of the protocol's multisig signing process enabled attackers to drain approximately USD 50 million from core markets on Arbitrum and BNB Chain and abuse open user approvals. Recovery and remediation efforts continued into 2026. On 2026-06-01, Radiant announced an orderly wind-down: active development ceased, borrowing was disabled across Core and RIZv1 markets, RDNT emissions were discontinued, and the protocol shifted to maintenance, withdrawals/repayments, user support and recovery work.

Customer result

Customer outcome

Claims ongoing

The January 2024 communal bad debt was addressed through DAO/OpEx recapitalization under RFP-27, but that is separate from the October 2024 user-loss remediation process. Radiant's June 2026 wind-down notice states that affected October 2024 users had not been remediated through recovered exploit funds, that no meaningful recovery had been obtained via zeroShadow, and that the remediation portal and claims infrastructure would remain available. Any future recovered funds are intended for affected users. No universal realized recovery percentage is asserted.

Estimated recovery
Unknown
Repayment started
Repayment completed
Confidence
High

Claim or case process →

Asset treatment

Terms risk

Customer-owned

Radiant is modeled as non-custodial DeFi lending rather than a platform-owned account balance. The October 2024 incident nevertheless demonstrates material administrative-control and approval risk: compromised multisig signing enabled hostile contract control, and open-ended token approvals allowed additional unauthorized transfers from user wallets. The June 2026 wind-down further limits new borrowing while preserving user-directed withdrawals, repayments and position management.

Affected product
Confidence
High

Source: Radiant Post-Mortem

Known unknowns

Uncertainty

Radiant's June 2026 announcement explicitly says the protocol is not being shut down immediately: front-end functionality, immutable contracts, position management and remediation/recovery support remain. CYA therefore uses status=limited rather than operations_ended. No universal realized recovery percentage is asserted for users affected by the October 2024 exploit.

Chronology

Historical record

exploitHigh impact2 sources

Radiant Arbitrum native USDC market exploit creates approximately 1,900 WETH bad debt

Radiant Capital's newly introduced native USDC market on Arbitrum was exploited through a flash-loan/loss-of-precision attack that manipulated the liquidityIndex while reserves were effectively empty. The attacker borrowed approximately 1,900 WETH. Radiant paused lending pools, later resumed unaffected markets, and used DAO/OpEx resources under RFP-27 to recapitalize the resulting communal bad debt.

The approximately USD 4.5 million value is a contemporaneous valuation of roughly 1,900 ETH/WETH and is distinct from the later October 2024 exploit. DAO repayment of communal bad debt is not treated as evidence about outcomes of the October incident.

exploitCritical impact3 sources

Radiant multisig compromise drains approximately USD 50 million from Arbitrum and BNB Chain markets

A targeted compromise of Radiant Capital's multisig signing workflow enabled attackers to obtain malicious signatures and take control of core lending contracts on Arbitrum and BNB Chain. Approximately USD 50 million was drained from core markets, and open-ended user token approvals were also abused to withdraw assets from user wallets. Recovery, tracking and remediation efforts followed, but Radiant later reported that affected users had not been fully remediated and that exploited funds remained unrecovered.

Official Radiant materials describe approximately USD 50M or USD 50M+; CYA records USD 50M as a conservative event metric and does not infer a universal final customer-loss figure.

OtherCritical impact2 sources

Radiant DAO begins orderly wind-down and shifts protocol to maintenance and recovery mode

After prolonged post-exploit recovery efforts failed to restore a viable operating runway, Radiant Capital DAO announced an orderly wind-down. Active development stopped, borrowing was disabled across Core and RIZv1 markets by setting caps to 1, RDNT emissions were discontinued, and treasury usage was restricted to essential operations. The protocol was not immediately shut down: the front end, immutable contracts, withdrawals, repayments, position management, remediation portal and recovery work were retained in a reduced maintenance state.

This is a wind-down transition rather than completed operations_ended. CYA should revisit the record after the announced front-end support window and if recovery/remediation infrastructure changes materially.

Source record

Evidence dossier

Filter by claim, reliability, source type, and whether evidence is linked to a specific event.

Showing 8 of 8 evidence records

customer outcome

1 sources
Official statementHigh

Radiant Capital DAO Community Remediation Plan

Radiant Capital · 2025-07-07

First-party remediation timeline and plan for users affected by the October 2024 exploit, including balance-checking and remediation infrastructure.

Event

5 sources
Official statementHighEvent linked

Post-Mortem Report: Radiant Capital

Radiant Capital · 2024-01-19

First-party post-mortem for the 2024-01-02 Arbitrum native USDC exploit. It describes liquidityIndex manipulation, approximately 1,900 WETH unauthorized borrowing, emergency pauses, market resumption and the RFP-27 bad-debt repayment path.

Official statementHighEvent linked

Radiant Post-Mortem

Radiant Capital · 2024-10-18

First-party post-mortem describing compromise of the multisig signing process, approximately USD 50 million drained from Arbitrum and BSC/BNB Chain core markets, abuse of open approvals and plans to redeploy the Aave V2 lending suite.

Official statementHighEvent linked

Radiant Capital Incident Update

Radiant Capital · 2024-12-06

First-party incident update describing an approximately USD 50 million loss and the Mandiant-assisted investigation into the targeted cyberattack.

status

2 sources

Comparative records

Independent archive

Help maintain customer-outcome records

Support court-document review, source preservation, corrections, broken-link replacement, and long-term archive maintenance. Support does not influence classifications or evidence standards.

Support CYA

Record maintenance

Report this record

Report incorrect dates, status, customer outcome, terms-risk interpretation, URL history, or missing evidence.

Submit correction →