The Radiant hacker seem to have trojaned several team members, making them believe they were signing a legit transaction


3 recorded changes
Want your article here?
Promote with Leviathan News

3 recorded changes
Want your article here?
Promote with Leviathan NewsRadiant Capital’s October 2024 exploit was not a simple smart-contract bug but a highly targeted social-engineering and malware operation. According to Mandiant’s investigation, North Korea-linked operators first tricked a Radiant team member with a malicious PDF delivered through Telegram; the file installed macOS malware that gave the attackers access to the victim’s device and let them manipulate transaction details during wallet signing. Daniel von Fange’s post aligns with that account, describing how the attacker “trojaned” several team members so they believed they were approving a legitimate transaction. The key technical point is that the attackers did not need to defeat Radiant’s wallet controls in the usual way. Instead, they used the compromised workstation to present benign-looking transaction data on the front end while substituting malicious payloads before signing, allowing them to authorize a transferOwnership() action that handed control of the lending pool to the attacker and ultimately enabled the theft of more than $50 million in assets. Mandiant and other reporting tied the operation to North Korea’s AppleJeus/Citrine Sleet cluster, housed within the Reconnaissance General Bureau, underscoring that state-linked groups continue to blend phishing, malware, and transaction manipulation to target crypto infrastructure. The incident matters because it shows a mature attack path against DeFi teams: compromise the human operator and endpoint, then exploit blind-signing and multisig workflow assumptions rather than the protocol itself. It also highlights a broader industry risk that standard transaction simulations and front-end checks can fail when the attacker controls the device generating or displaying the signing request.
AI-generated background, compiled from web sources — not editorial content.

Prnewswire ·

𝕏/0xPrince ·

Chosun ·

decrypt.co ·

Membranelabs ·

𝕏/@officer_secret ·

Prnewswire ·

𝕏/0xPrince ·

Chosun ·

decrypt.co ·

Membranelabs ·

𝕏/@officer_secret ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?