Radiant Capital hack
A cross-chain lending protocol drained of about $50M on October 16, 2024. Mandiant attributed it to a North Korea-linked actor (UNC4736 / AppleJeus) that used a fake-contractor Telegram lure to plant macOS malware on developers' machines and forge multisig approvals.
Also known as: Radiant Capital, Radiant, RDNT
Summary
Radiant Capital was a cross-chain lending protocol. On October 16, 2024, attackers seized control of its lending-pool contracts and drained about $50 million from its Arbitrum and BNB Chain markets. [1][2]
Method and attribution
According to a December 2024 update from Radiant and Mandiant, the operation began in September 2024 with a Telegram message impersonating a former contractor that delivered a zipped decoy PDF carrying the macOS backdoor "INLETDRIFT." The malware let attackers display legitimate-looking transactions to signers while signing malicious ones, defeating hardware wallets and simulation checks, and ultimately collecting enough multisig approvals to take over the contracts. Mandiant attributed the attack with high confidence to a DPRK-nexus group, UNC4736 (also tracked as AppleJeus / Citrine Sleet). Radiant had also suffered a separate ~$4.5M flash-loan hack in January 2024. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
World Liberty Financial (WLFI) — Justin Sun token freezeProjectsWLFI, a DeFi project linked to Donald Trump and his family, blacklisted/froze the wallet of major investor Justin Sun in Sept 2025 — ~540–595M unlocked WLFI tokens (~$107M) plus ~2.4B locked. Sun sued, alleging an undisclosed admin 'blacklist backdoor'; WLFI denied it and threatened a countersuit. The dispute is ongoing.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
