Radiant Capital’s October 2024 exploit was not a simple smart-contract bug but a highly targeted social-engineering and malware operation. According to Mandiant’s investigation, North Korea-linked operators first tricked a Radiant team member with a malicious PDF delivered through Telegram; the file installed macOS malware that gave the attackers access to the victim’s device and let them manipulate transaction details during wallet signing. Daniel von Fange’s post aligns with that account, describing how the attacker “trojaned” several team members so they believed they were approving a legitimate transaction. The key technical point is that the attackers did not need to defeat Radiant’s wallet controls in the usual way. Instead, they used the compromised workstation to present benign-looking transaction data on the front end while substituting malicious payloads before signing, allowing them to authorize a transferOwnership() action that handed control of the lending pool to the attacker and ultimately enabled the theft of more than $50 million in assets. Mandiant and other reporting tied the operation to North Korea’s AppleJeus/Citrine Sleet cluster, housed within the Reconnaissance General Bureau, underscoring that state-linked groups continue to blend phishing, malware, and transaction manipulation to target crypto infrastructure. The incident matters because it shows a mature attack path against DeFi teams: compromise the human operator and endpoint, then exploit blind-signing and multisig workflow assumptions rather than the protocol itself. It also highlights a broader industry risk that standard transaction simulations and front-end checks can fail when the attacker controls the device generating or displaying the signing request.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Transaction

Open Transaction Layer unites major crypto and finance players to set interoperability standard for global onchain finance

Open Transaction Layer unites major crypto and finance players to set interoperability standard for global onchain finance

Prnewswire ·

Many people try crypto once and never return, not because they explored its depth, but because their first interaction felt confusing, transactional, and stacked in favor of insiders. First impressions calcify fast, especially when expectations don’t match outcomes.

Many people try crypto once and never return, not because they explored its depth, but because their first interaction felt confusing, transactional, and stacked in favor of insiders. First impressions calcify fast, especially when expectations don’t match outcomes.

𝕏/0xPrince ·

Mirae Asset Group pursues acquisition of fourth-largest crypto exchange Korbit. Transaction valued at 100-140 billion Korean won as details remain fluid. The deal would be led by Mirae Asset Consulting, a non-financial subsidiary, which has signed a memorandum of understanding with Korbit’s major shareholders.

Mirae Asset Group pursues acquisition of fourth-largest crypto exchange Korbit. Transaction valued at 100-140 billion Korean won as details remain fluid. The deal would be led by Mirae Asset Consulting, a non-financial subsidiary, which has signed a memorandum of understanding with Korbit’s major shareholders.

Chosun ·

Stablecoin supply climbed past $314B in 2025, but usage told a different story as Tether led transaction activity, followed by RLUSD and USDC, while the Trump-backed USD1 surged into the top tier months after launch.

Stablecoin supply climbed past $314B in 2025, but usage told a different story as Tether led transaction activity, followed by RLUSD and USDC, while the Trump-backed USD1 surged into the top tier months after launch.

decrypt.co ·

First institutional stablecoin-for-stablecoin repo on a public blockchain settled and serviced on Membrane. The transaction marks the creation of a standardized, institutional-grade stablecoin funding market that brings familiar TradFi liquidity tools directly onto public blockchain rails. This structure represents the first time a native stablecoin has served as the asset leg in an institutional repo. Solstice posted its native stablecoin, USX, as the asset leg, while Cor Prime provided USDC as the cash leg.

First institutional stablecoin-for-stablecoin repo on a public blockchain settled and serviced on Membrane. The transaction marks the creation of a standardized, institutional-grade stablecoin funding market that brings familiar TradFi liquidity tools directly onto public blockchain rails. This structure represents the first time a native stablecoin has served as the asset leg in an institutional repo. Solstice posted its native stablecoin, USX, as the asset leg, while Cor Prime provided USDC as the cash leg.

Membranelabs ·

Address poisoning attacks exploit look-alike wallet addresses to trick users into misdirected transfers. Staying safe requires careful address verification, avoiding transaction-history copying, and using tools like whitelists, ENS, and hardware wallets.

Address poisoning attacks exploit look-alike wallet addresses to trick users into misdirected transfers. Staying safe requires careful address verification, avoiding transaction-history copying, and using tools like whitelists, ENS, and hardware wallets.

𝕏/@officer_secret ·

Comments