BTC $83,201.75 -1.05%
ETH $2,679.61 +0.20%
BNB $760.45 -2.31%
XRP $1.49 -1.66%
SOL $118.16 -2.89%
TRX $0.3352 +0.37%
DOGE $0.0938 -2.79%
ADA $0.2469 -3.32%
BCH $309.01 -6.17%
LINK $15.47 +10.21%
HYPE $86.60 -4.26%
AAVE $149.19 -2.72%
SUI $1.14 -9.33%
XLM $0.2286 +5.04%
ZEC $1,454.28 -7.71%
AAPL $338.34 -0.53%
AMZN $246.41 -1.17%
GOOGL $342.44 -0.13%
MSFT $509.07 -1.25%
META $717.37 -2.87%
NVDA $228.72 +1.74%
TSLA $357.79 -3.72%
SNDK $1,705.77 -2.63%
INTC $115.26 -5.27%
SPCX $145.94 -2.28%
MU $1,049.81 -2.43%
AMD $607.29 -3.10%
BTC $83,201.75 -1.05%
ETH $2,679.61 +0.20%
BNB $760.45 -2.31%
XRP $1.49 -1.66%
SOL $118.16 -2.89%
TRX $0.3352 +0.37%
DOGE $0.0938 -2.79%
ADA $0.2469 -3.32%
BCH $309.01 -6.17%
LINK $15.47 +10.21%
HYPE $86.60 -4.26%
AAVE $149.19 -2.72%
SUI $1.14 -9.33%
XLM $0.2286 +5.04%
ZEC $1,454.28 -7.71%
AAPL $338.34 -0.53%
AMZN $246.41 -1.17%
GOOGL $342.44 -0.13%
MSFT $509.07 -1.25%
META $717.37 -2.87%
NVDA $228.72 +1.74%
TSLA $357.79 -3.72%
SNDK $1,705.77 -2.63%
INTC $115.26 -5.27%
SPCX $145.94 -2.28%
MU $1,049.81 -2.43%
AMD $607.29 -3.10%

Slow Fog releases Radiant Capital security incident analysis: Attackers illegally control 3 owner permissions in the multi-signature wallet

2024-10-17 12:17:18

ChainCatcher news, Slow Mist releases an analysis of the Radiant Capital security incident (Arbitrum chain):

Radiant Capital uses a multi-signature wallet (0x111ceeee040739fd91d29c34c33e6b3e112f2177) to manage key operations such as contract upgrades and fund transfers. However, the attacker illegally gained control of the owner permissions of 3 out of the 11 owners of the multi-signature wallet.

Since Radiant Capital's multi-signature wallet employs a 3/11 signature verification model, the attacker first used the private keys of these 3 owners to perform off-chain signatures, and then initiated an on-chain transaction from the multi-signature wallet to transfer the ownership of the LendingPoolAddressesProvider contract to a malicious contract controlled by the attacker.

Subsequently, the malicious contract called the setLendingPoolImpl function of the LendingPoolAddressesProvider contract, upgrading the underlying logic contract of the Radiant lending pool to a malicious backdoor contract (0xf0c0a1a19886791c2dd6af71307496b1e16aa232).

Finally, the attacker executed the backdoor function, transferring funds from various lending markets into the attack contract.

Previous news, Radiant Capital suffered a cyber attack, resulting in losses exceeding $50 million.

app_icon
ChainCatcher Building the Web3 world with innovations.