BTC $83,353.92 -1.53%
ETH $2,676.69 -0.27%
BNB $762.01 -2.01%
XRP $1.49 -2.25%
SOL $117.97 -3.96%
TRX $0.3356 +0.63%
DOGE $0.0932 -3.82%
ADA $0.2439 -4.39%
BCH $307.60 -7.55%
LINK $15.14 +8.06%
HYPE $86.87 -5.02%
AAVE $146.22 -5.27%
SUI $1.13 -9.50%
XLM $0.2249 +3.99%
ZEC $1,463.63 -8.43%
AAPL $338.51 -0.46%
AMZN $246.40 -1.56%
GOOGL $342.54 -0.45%
MSFT $509.65 -1.55%
META $717.60 -4.29%
NVDA $229.26 +1.84%
TSLA $357.98 -4.10%
SNDK $1,712.58 -4.01%
INTC $115.93 -7.39%
SPCX $145.91 -2.29%
MU $1,053.93 -3.89%
AMD $609.57 -4.24%
BTC $83,353.92 -1.53%
ETH $2,676.69 -0.27%
BNB $762.01 -2.01%
XRP $1.49 -2.25%
SOL $117.97 -3.96%
TRX $0.3356 +0.63%
DOGE $0.0932 -3.82%
ADA $0.2439 -4.39%
BCH $307.60 -7.55%
LINK $15.14 +8.06%
HYPE $86.87 -5.02%
AAVE $146.22 -5.27%
SUI $1.13 -9.50%
XLM $0.2249 +3.99%
ZEC $1,463.63 -8.43%
AAPL $338.51 -0.46%
AMZN $246.40 -1.56%
GOOGL $342.54 -0.45%
MSFT $509.65 -1.55%
META $717.60 -4.29%
NVDA $229.26 +1.84%
TSLA $357.98 -4.10%
SNDK $1,712.58 -4.01%
INTC $115.93 -7.39%
SPCX $145.91 -2.29%
MU $1,053.93 -3.89%
AMD $609.57 -4.24%

Slow Fog releases Radiant Capital security incident analysis: Attackers illegally control 3 owner permissions in the multi-signature wallet

2024-10-17 12:17:18

ChainCatcher news, Slow Mist releases an analysis of the Radiant Capital security incident (Arbitrum chain):

Radiant Capital uses a multi-signature wallet (0x111ceeee040739fd91d29c34c33e6b3e112f2177) to manage key operations such as contract upgrades and fund transfers. However, the attacker illegally gained control of the owner permissions of 3 out of the 11 owners of the multi-signature wallet.

Since Radiant Capital's multi-signature wallet employs a 3/11 signature verification model, the attacker first used the private keys of these 3 owners to perform off-chain signatures, and then initiated an on-chain transaction from the multi-signature wallet to transfer the ownership of the LendingPoolAddressesProvider contract to a malicious contract controlled by the attacker.

Subsequently, the malicious contract called the setLendingPoolImpl function of the LendingPoolAddressesProvider contract, upgrading the underlying logic contract of the Radiant lending pool to a malicious backdoor contract (0xf0c0a1a19886791c2dd6af71307496b1e16aa232).

Finally, the attacker executed the backdoor function, transferring funds from various lending markets into the attack contract.

Previous news, Radiant Capital suffered a cyber attack, resulting in losses exceeding $50 million.

app_icon
ChainCatcher Building the Web3 world with innovations.