BTC $84,840.88 -2.41%
ETH $2,680.78 -2.92%
BNB $773.51 -1.13%
XRP $1.49 -3.14%
SOL $119.45 -2.58%
TRX $0.3357 +0.29%
DOGE $0.0927 -4.40%
ADA $0.2448 -4.63%
BCH $311.45 -1.60%
LINK $13.87 -3.48%
HYPE $88.42 -2.55%
AAVE $181.01 -1.19%
SUI $1.17 -2.79%
XLM $0.2150 -4.53%
ZEC $1,301.71 -6.47%
AAPL $333.20 +0.50%
AMZN $251.85 +0.19%
GOOGL $343.15 -0.04%
MSFT $517.39 +0.32%
META $728.08 -0.42%
NVDA $234.35 -1.27%
TSLA $370.94 +0.48%
SNDK $1,716.93 -1.35%
INTC $117.99 -4.95%
SPCX $159.12 +1.72%
MU $1,069.59 -1.86%
AMD $632.29 -1.08%
BTC $84,840.88 -2.41%
ETH $2,680.78 -2.92%
BNB $773.51 -1.13%
XRP $1.49 -3.14%
SOL $119.45 -2.58%
TRX $0.3357 +0.29%
DOGE $0.0927 -4.40%
ADA $0.2448 -4.63%
BCH $311.45 -1.60%
LINK $13.87 -3.48%
HYPE $88.42 -2.55%
AAVE $181.01 -1.19%
SUI $1.17 -2.79%
XLM $0.2150 -4.53%
ZEC $1,301.71 -6.47%
AAPL $333.20 +0.50%
AMZN $251.85 +0.19%
GOOGL $343.15 -0.04%
MSFT $517.39 +0.32%
META $728.08 -0.42%
NVDA $234.35 -1.27%
TSLA $370.94 +0.48%
SNDK $1,716.93 -1.35%
INTC $117.99 -4.95%
SPCX $159.12 +1.72%
MU $1,069.59 -1.86%
AMD $632.29 -1.08%

Slow Fog releases Radiant Capital security incident analysis: Attackers illegally control 3 owner permissions in the multi-signature wallet

2024-10-17 12:17:18

ChainCatcher news, Slow Mist releases an analysis of the Radiant Capital security incident (Arbitrum chain):

Radiant Capital uses a multi-signature wallet (0x111ceeee040739fd91d29c34c33e6b3e112f2177) to manage key operations such as contract upgrades and fund transfers. However, the attacker illegally gained control of the owner permissions of 3 out of the 11 owners of the multi-signature wallet.

Since Radiant Capital's multi-signature wallet employs a 3/11 signature verification model, the attacker first used the private keys of these 3 owners to perform off-chain signatures, and then initiated an on-chain transaction from the multi-signature wallet to transfer the ownership of the LendingPoolAddressesProvider contract to a malicious contract controlled by the attacker.

Subsequently, the malicious contract called the setLendingPoolImpl function of the LendingPoolAddressesProvider contract, upgrading the underlying logic contract of the Radiant lending pool to a malicious backdoor contract (0xf0c0a1a19886791c2dd6af71307496b1e16aa232).

Finally, the attacker executed the backdoor function, transferring funds from various lending markets into the attack contract.

Previous news, Radiant Capital suffered a cyber attack, resulting in losses exceeding $50 million.

app_icon
ChainCatcher Building the Web3 world with innovations.