BTC $77,788.74 +0.71%
ETH $2,517.15 -0.12%
BNB $724.11 -0.55%
XRP $1.38 +0.85%
SOL $101.14 -0.68%
TRX $0.3388 -0.32%
DOGE $0.0840 -0.84%
ADA $0.2079 +0.35%
BCH $224.24 -0.43%
LINK $11.40 -0.73%
HYPE $79.90 +0.91%
AAVE $126.19 -0.84%
SUI $0.7179 -0.97%
XLM $0.1814 +0.84%
ZEC $1,111.27 -1.95%
AAPL $328.81 -1.30%
AMZN $254.32 -1.01%
GOOGL $336.01 -1.53%
MSFT $493.46 -0.47%
META $640.54 -1.17%
NVDA $214.95 -1.34%
TSLA $360.71 -1.86%
SNDK $1,566.96 -3.53%
INTC $98.67 -2.76%
SPCX $148.71 -1.05%
MU $939.78 -2.86%
AMD $500.31 -2.64%
BTC $77,788.74 +0.71%
ETH $2,517.15 -0.12%
BNB $724.11 -0.55%
XRP $1.38 +0.85%
SOL $101.14 -0.68%
TRX $0.3388 -0.32%
DOGE $0.0840 -0.84%
ADA $0.2079 +0.35%
BCH $224.24 -0.43%
LINK $11.40 -0.73%
HYPE $79.90 +0.91%
AAVE $126.19 -0.84%
SUI $0.7179 -0.97%
XLM $0.1814 +0.84%
ZEC $1,111.27 -1.95%
AAPL $328.81 -1.30%
AMZN $254.32 -1.01%
GOOGL $336.01 -1.53%
MSFT $493.46 -0.47%
META $640.54 -1.17%
NVDA $214.95 -1.34%
TSLA $360.71 -1.86%
SNDK $1,566.96 -3.53%
INTC $98.67 -2.76%
SPCX $148.71 -1.05%
MU $939.78 -2.86%
AMD $500.31 -2.64%

Slow Fog releases Radiant Capital security incident analysis: Attackers illegally control 3 owner permissions in the multi-signature wallet

2024-10-17 12:17:18

ChainCatcher news, Slow Mist releases an analysis of the Radiant Capital security incident (Arbitrum chain):

Radiant Capital uses a multi-signature wallet (0x111ceeee040739fd91d29c34c33e6b3e112f2177) to manage key operations such as contract upgrades and fund transfers. However, the attacker illegally gained control of the owner permissions of 3 out of the 11 owners of the multi-signature wallet.

Since Radiant Capital's multi-signature wallet employs a 3/11 signature verification model, the attacker first used the private keys of these 3 owners to perform off-chain signatures, and then initiated an on-chain transaction from the multi-signature wallet to transfer the ownership of the LendingPoolAddressesProvider contract to a malicious contract controlled by the attacker.

Subsequently, the malicious contract called the setLendingPoolImpl function of the LendingPoolAddressesProvider contract, upgrading the underlying logic contract of the Radiant lending pool to a malicious backdoor contract (0xf0c0a1a19886791c2dd6af71307496b1e16aa232).

Finally, the attacker executed the backdoor function, transferring funds from various lending markets into the attack contract.

Previous news, Radiant Capital suffered a cyber attack, resulting in losses exceeding $50 million.

app_icon
ChainCatcher Building the Web3 world with innovations.