Radix Foundation: Attackers exploited engine vulnerabilities to steal assets, causing the network to temporarily lose activity
Radix Foundation released an incident report stating that attackers exploited a previously undiscovered vulnerability in Radix Engine to extract assets from a third-party vault without the owner's authorization, and then sold them across chains to networks such as Ethereum, BNB Chain, and Solana via Hyperlane.
The vulnerability originated from a code compilation in June 2023, and an independent security audit conducted by Zellic in August 2024 also did not identify the issue. About 3 hours after the incident occurred, Radix validators proactively took offline enough staked shares to prevent the network from reaching consensus, thereby stopping further exploitation of the vulnerability; affected assets included ETH, WBTC, USDT, USDC, BNB, and SOL.
Radix stated that the vulnerability has been fixed and has undergone independent review and testing, and the network recovery is currently being advanced.






